MegaBBS 'upload.asp' Cross-Site Scripting Vulnerability
BID:27368
Info
MegaBBS 'upload.asp' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 27368 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0436 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Doz is credited with the discovery of this vulnerability. |
| Vulnerable: |
PD9 Software MegaBBS 1.5.14b |
| Not Vulnerable: |
PD9 Software MegaBBS 2.2 |
Discussion
MegaBBS 'upload.asp' Cross-Site Scripting Vulnerability
MegaBBS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
MegaBBS 1.5.14b is vulnerable; other versions may also be affected.
MegaBBS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
MegaBBS 1.5.14b is vulnerable; other versions may also be affected.
Exploit / POC
MegaBBS 'upload.asp' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
http://www.example.com/path/profile-upload/upload.asp?target=code
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
http://www.example.com/path/profile-upload/upload.asp?target=code
Solution / Fix
MegaBBS 'upload.asp' Cross-Site Scripting Vulnerability
Solution:
Users can upgrade to MegaBBS 2.2 to address this issue. Please see the references for more information.
Solution:
Users can upgrade to MegaBBS 2.2 to address this issue. Please see the references for more information.
References
MegaBBS 'upload.asp' Cross-Site Scripting Vulnerability
References:
References:
- Homepage (PD9 Software)
- MegaBBS ASP Forum Cross-Site Scripting ([email protected])