vBulletin Moderation Control Panel 'redirect' Parameter Cross-Site Scripting Vulnerability
BID:29817
Info
vBulletin Moderation Control Panel 'redirect' Parameter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 29817 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2008 12:00AM |
| Updated: | Jun 23 2008 04:21PM |
| Credit: | Jessica Hope |
| Vulnerable: |
VBulletin VBulletin 3.7.1 PL1 VBulletin VBulletin 3.7.1 VBulletin VBulletin 3.7 Gold VBulletin VBulletin 3.6.10 PL1 VBulletin VBulletin 3.6.10 VBulletin VBulletin 3.6.8 VBulletin VBulletin 3.6.7 VBulletin VBulletin 3.6.6 VBulletin VBulletin 3.6.5 VBulletin VBulletin 3.6.4 VBulletin VBulletin 3.6.3 VBulletin VBulletin 3.6.2 VBulletin VBulletin 3.6.1 VBulletin VBulletin 3.6 |
| Not Vulnerable: |
VBulletin VBulletin 3.7.1 PL2 VBulletin VBulletin 3.6.10 PL2 |
Discussion
vBulletin Moderation Control Panel 'redirect' Parameter Cross-Site Scripting Vulnerability
vBulletin is prone to a cross-site scripting vulnerability that occurs in the MCP (moderation control panel) because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
vBulletin 3.7.1 PL1 and 3.6.10 PL1 are vulnerable; prior versions may also be affected.
vBulletin is prone to a cross-site scripting vulnerability that occurs in the MCP (moderation control panel) because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
vBulletin 3.7.1 PL1 and 3.6.10 PL1 are vulnerable; prior versions may also be affected.
Exploit / POC
vBulletin Moderation Control Panel 'redirect' Parameter Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/vB3/modcp/index.php?redirect=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K
http://www.example.com/vB3/modcp/index.php?redirect={XSS}
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/vB3/modcp/index.php?redirect=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K
http://www.example.com/vB3/modcp/index.php?redirect={XSS}
Solution / Fix
vBulletin Moderation Control Panel 'redirect' Parameter Cross-Site Scripting Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
vBulletin Moderation Control Panel 'redirect' Parameter Cross-Site Scripting Vulnerability
References:
References:
- 3.7.1 Package Updated (vBulletin)
- vBulletin Homepage (vBulletin)