TinyBrowser Multiple Vulnerabilities
BID:35855
Info
TinyBrowser Multiple Vulnerabilities
| Bugtraq ID: | 35855 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2009 12:00AM |
| Updated: | May 19 2010 07:22AM |
| Credit: | Aung Khant |
| Vulnerable: |
Lunarvis TinyBrowser 1.41.6 Joomla Joomla 1.5.12 CompactCMS CompactCMS 1.4 B-hind CMS B-hind CMS 0 |
| Not Vulnerable: | |
Discussion
TinyBrowser Multiple Vulnerabilities
TinyBrowser is prone to multiple vulnerabilities, including cross-site scripting and security-bypass issues.
Attackers can exploit these issues to host arbitrary content on a vulnerable computer, upload and delete arbitrary files, create arbitrary folders, and carry out cross-site scripting attacks, which can lead to various other attacks against the computer.
TinyBrowser 1.41.6 is vulnerable; other versions may also be affected.
Some of these issues may be related to the vulnerabilities described in BID 35780 (Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness).
TinyBrowser is prone to multiple vulnerabilities, including cross-site scripting and security-bypass issues.
Attackers can exploit these issues to host arbitrary content on a vulnerable computer, upload and delete arbitrary files, create arbitrary folders, and carry out cross-site scripting attacks, which can lead to various other attacks against the computer.
TinyBrowser 1.41.6 is vulnerable; other versions may also be affected.
Some of these issues may be related to the vulnerabilities described in BID 35780 (Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness).
Exploit / POC
TinyBrowser Multiple Vulnerabilities
To host arbitrary content:
1. Create a hidden directory by requesting the following URI:
http://www.example.com/[PATH]/upload.php?type=file&folder=.hostmyfiles
2. Upload files to the folder created.
The following example URI is available for the cross-site scripting issue:
http://www.example.com/upload.php?badfiles=1"><script>alert(/XSS/)</script>
To host arbitrary content:
1. Create a hidden directory by requesting the following URI:
http://www.example.com/[PATH]/upload.php?type=file&folder=.hostmyfiles
2. Upload files to the folder created.
The following example URI is available for the cross-site scripting issue:
http://www.example.com/upload.php?badfiles=1"><script>alert(/XSS/)</script>
Solution / Fix
TinyBrowser Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TinyBrowser Multiple Vulnerabilities
References:
References:
- CompactCMS 1.4.0 (tiny_mce) Remote File Upload (ITSecTeam)
- TinyBrowser (Lunarvis)