DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
BID:27619
Info
DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 27619 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7036 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Lostmon lords <[email protected]> discovered these vulnerabilities. |
| Vulnerable: |
E-Xoops E-Xoops 1.0.8 bcoos bcoos 1.1.11 |
| Not Vulnerable: | |
Discussion
DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
DevTracker module for bcoos and E-xoops is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect the following versions:
bcoos 1.1.11 (and earlier) with DevTracker 3.0
E-xoops 1.0.8 (and earlier) with DevTracker v0.20
Other versions may also be vulnerable.
DevTracker module for bcoos and E-xoops is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect the following versions:
bcoos 1.1.11 (and earlier) with DevTracker 3.0
E-xoops 1.0.8 (and earlier) with DevTracker v0.20
Other versions may also be vulnerable.
Exploit / POC
DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URIs are available:
http://www.example.com/modules/devtracker/index.php?proj_id=1&order_by=priority&direction=ASCquot;><script>alert()</script> http://www.example.com/modules/devtracker/index.php?proj_id=1&order_by=priorityquot;><script>alert()</script>&direction=ASC
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URIs are available:
http://www.example.com/modules/devtracker/index.php?proj_id=1&order_by=priority&direction=ASCquot;><script>alert()</script> http://www.example.com/modules/devtracker/index.php?proj_id=1&order_by=priorityquot;><script>alert()</script>&direction=ASC
Solution / Fix
DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- bcoos & E-xoops DevTracker module two variables XSS (Lostmon)
- bcoos Homepage (bcoos)
- DevTracker Homepage (DevTracker)
- E-Xoops Home Page (E-Xoops)