INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BID:16123
Info
INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 16123 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2006 12:00AM |
| Updated: | Jan 03 2006 12:00AM |
| Credit: | r0t is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
INCOGEN BugPort 1.147 INCOGEN BugPort 1.134 INCOGEN BugPort 1.133 INCOGEN BugPort 1.129 INCOGEN BugPort 1.125 INCOGEN BugPort 1.119 INCOGEN BugPort 1.117 INCOGEN BugPort 1.109 INCOGEN BugPort 1.108 INCOGEN BugPort 1.101 INCOGEN BugPort 1.099 INCOGEN BugPort 1.098 INCOGEN BugPort 1.097 INCOGEN BugPort 1.096 INCOGEN BugPort 1.095 INCOGEN BugPort 1.094 INCOGEN BugPort 1.093 INCOGEN BugPort 1.092 INCOGEN BugPort 1.091 INCOGEN BugPort 1.090 |
| Not Vulnerable: | |
Discussion
INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
Bugport is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Bugport is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
No exploit is required.
Example URI have been provided:
http://www.example.com/index.php?view=AddToFavoriteItemSetView&ids%5B0%5D=[XSS]
http://www.example.com/index.php?view=AddRelatedDevelopmentItemFormView&report_id=9&action=[XSS]
http://www.example.com/index.php?view=AddRelatedDevelopmentItemFormView&report_id=[XSS]
http://www.example.com/index.php?view=DevelopmentItemResultsView&devWherePair%5B0%5D=state_id+%3C+%3F++AND++MATCH+%28report%2Csubject%2Cdevelplan%2Cfixednotes%2Crepsteps%29+AGAINST+%28%3F++IN+BOOLEAN+MODE%29&devWherePair%5B1%5D%5B0%5D=240&devWherePair%5B1%5D%5B1%5D=[XSS]
http://www.example.com/index.php?view=DevelopmentItemResultsView&where=project_id+%3D+%3F&orderBy=priority_id+DESC&binds%5B0%5D=[XSS]
No exploit is required.
Example URI have been provided:
http://www.example.com/index.php?view=AddToFavoriteItemSetView&ids%5B0%5D=[XSS]
http://www.example.com/index.php?view=AddRelatedDevelopmentItemFormView&report_id=9&action=[XSS]
http://www.example.com/index.php?view=AddRelatedDevelopmentItemFormView&report_id=[XSS]
http://www.example.com/index.php?view=DevelopmentItemResultsView&devWherePair%5B0%5D=state_id+%3C+%3F++AND++MATCH+%28report%2Csubject%2Cdevelplan%2Cfixednotes%2Crepsteps%29+AGAINST+%28%3F++IN+BOOLEAN+MODE%29&devWherePair%5B1%5D%5B0%5D=240&devWherePair%5B1%5D%5B1%5D=[XSS]
http://www.example.com/index.php?view=DevelopmentItemResultsView&where=project_id+%3D+%3F&orderBy=priority_id+DESC&binds%5B0%5D=[XSS]
Solution / Fix
INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
INCOGEN Bugport Index.PHP Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- BugPort Homepage (INCOGEN)
- BugPort Multiple vuln. (r0t)