68 Classifieds Multiple Cross-Site Scripting Vulnerabilities
BID:36208
Info
68 Classifieds Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 36208 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2009 12:00AM |
| Updated: | Sep 10 2009 09:01PM |
| Credit: | Moudi |
| Vulnerable: |
68 Classifieds 68 Classifieds 4.1.4 68 Classifieds 68 Classifieds 4.1 |
| Not Vulnerable: |
68 Classifieds 68 Classifieds 4.1.5 |
Discussion
68 Classifieds Multiple Cross-Site Scripting Vulnerabilities
'68 Classifieds' is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect 68 Classifieds 4.1; other versions may also be affected.
'68 Classifieds' is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect 68 Classifieds 4.1; other versions may also be affected.
Exploit / POC
68 Classifieds Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/category.php?cat=[code]
http://www.example.com/login.php?goto=usercheckout.php&view=[code]
http://www.example.com/searchresults.php?page=[code]
http://www.example.com/toplistings.php?page=[code]
http://www.example.com/viewlisting.php?view=[code]
http://www.example.com/viewmember.php?member=[code]
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/category.php?cat=[code]
http://www.example.com/login.php?goto=usercheckout.php&view=[code]
http://www.example.com/searchresults.php?page=[code]
http://www.example.com/toplistings.php?page=[code]
http://www.example.com/viewlisting.php?view=[code]
http://www.example.com/viewmember.php?member=[code]
Solution / Fix
68 Classifieds Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has addressed this issue in 68 Classifieds 4.1.5 and later. Please contact the vendor for details.
Solution:
The vendor has addressed this issue in 68 Classifieds 4.1.5 and later. Please contact the vendor for details.
References
68 Classifieds Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- 68 Classifieds Homepage (68 Classifieds)
- Security Issue with included Template switcher (Eric Barnes)