TorrentTrader 'msg' Parameter HTML Injection Vulnerability
BID:28082
Info
TorrentTrader 'msg' Parameter HTML Injection Vulnerability
| Bugtraq ID: | 28082 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1173 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2008 12:00AM |
| Updated: | Apr 29 2009 08:56PM |
| Credit: | Dominus is credited with discovering this vulnerability. |
| Vulnerable: |
TorrentTrader TorrentTrader Classic Edition 1.08 |
| Not Vulnerable: | |
Discussion
TorrentTrader 'msg' Parameter HTML Injection Vulnerability
TorrentTrader is prone to an HTML-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
NOTE: This BID was previously titled 'TorrentTrader 'msg' Parameter Cross Site Scripting Vulnerability'. Following further analysis, the title and multiple details throughout have been changed to better document the issue.
TorrentTrader Classic 1.08 is affected; other versions may also be vulnerable.
TorrentTrader is prone to an HTML-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
NOTE: This BID was previously titled 'TorrentTrader 'msg' Parameter Cross Site Scripting Vulnerability'. Following further analysis, the title and multiple details throughout have been changed to better document the issue.
TorrentTrader Classic 1.08 is affected; other versions may also be vulnerable.
Exploit / POC
TorrentTrader 'msg' Parameter HTML Injection Vulnerability
An attacker can use a browser to exploit this issue.
The following example URI is available:
An attacker can use a browser to exploit this issue.
The following example URI is available:
Solution / Fix
TorrentTrader 'msg' Parameter HTML Injection Vulnerability
Solution:
This issue has been addressed in the revision 25/03/08 of Torrent Classic 1.08. Please see the references for more information.
Solution:
This issue has been addressed in the revision 25/03/08 of Torrent Classic 1.08. Please see the references for more information.
References
TorrentTrader 'msg' Parameter HTML Injection Vulnerability
References:
References:
- Release Name: FINAL v1.08 (TorrentTrader)
- TorrentTrader Homepage (TorrentTrader)
- Cross-site Scripting and CSRF in TorrentTrader Classic v1.08 ("Valery Marchuk"
)