O'Reilly WebBoard Pager Hostile JavaScript Vulnerability
BID:2814
Info
O'Reilly WebBoard Pager Hostile JavaScript Vulnerability
| Bugtraq ID: | 2814 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0743 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Reported to bugtraq by "Helmuth Antholzer" <[email protected]> on June 2, 2001 |
| Vulnerable: |
OReilly Software WebBoard 4.10.30 |
| Not Vulnerable: |
OReilly Software WebBoard 4.2 |
Discussion
O'Reilly WebBoard Pager Hostile JavaScript Vulnerability
O'Reilly WebBoard is a conferencing utility, forum, threaded discussion and real-time chat server.
Versions of WebBoard are vulnerable to a JavaScript code execution bug which may allow a remote denial of service against a target WebBoard user's system.
An attacker can compose a message in WebBoard's interactive messaging (paging) function, containing certain escape characters and JavaScript commands, and send the page to a target user. Upon receiving the message, the target client will improperly execute the JavaScript embedded in the page, which could result in the appearance of multiple message windows.
WebBoard is no longer supported by O'Reilly, it is currently maintained by ChatSpace, Inc.
O'Reilly WebBoard is a conferencing utility, forum, threaded discussion and real-time chat server.
Versions of WebBoard are vulnerable to a JavaScript code execution bug which may allow a remote denial of service against a target WebBoard user's system.
An attacker can compose a message in WebBoard's interactive messaging (paging) function, containing certain escape characters and JavaScript commands, and send the page to a target user. Upon receiving the message, the target client will improperly execute the JavaScript embedded in the page, which could result in the appearance of multiple message windows.
WebBoard is no longer supported by O'Reilly, it is currently maintained by ChatSpace, Inc.
Exploit / POC
O'Reilly WebBoard Pager Hostile JavaScript Vulnerability
An example of malicious javascript:
\');for(i=0;i<100000;i++) alert("not nice"); /
An example of malicious javascript:
\');for(i=0;i<100000;i++) alert("not nice"); /
Solution / Fix
O'Reilly WebBoard Pager Hostile JavaScript Vulnerability
Solution:
WebBoard is no longer supported by O'Reilly, it is currently maintained by ChatSpace, Inc.
ChatSpace has released version 4.2 which is not vulnerable to this issue:
OReilly Software WebBoard 4.10.30
Solution:
WebBoard is no longer supported by O'Reilly, it is currently maintained by ChatSpace, Inc.
ChatSpace has released version 4.2 which is not vulnerable to this issue:
OReilly Software WebBoard 4.10.30