Powie PForum Username Cross-Site Scripting Vulnerability
BID:4165
Info
Powie PForum Username Cross-Site Scripting Vulnerability
| Bugtraq ID: | 4165 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0319 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability was submitted to BugTraq on February 22nd, 2002 by Jens Liebchen <[email protected]>. |
| Vulnerable: |
Powie PForum 1.14 Powie PForum 1.13 Powie PForum 1.12 Powie PForum 1.11 |
| Not Vulnerable: |
Powie PForum 1.15 |
Discussion
Powie PForum Username Cross-Site Scripting Vulnerability
Powie PForum is web forum software, written in PHP and back-ended by MySQL. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
PForum is prone to cross-site scripting attacks. It is possible for an attacker to construct a malicious link which includes arbitrary script code. In particular, the username URL parameter does not filter variations of HTML tags. A legitimate user who browses the malicious link will have the attacker-supplied script code executed in their browser, in their context of the website running the vulnerable software.
This may enable an attacker to steal cookie-based authentication credentials from the legitimate user.
Powie PForum is web forum software, written in PHP and back-ended by MySQL. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
PForum is prone to cross-site scripting attacks. It is possible for an attacker to construct a malicious link which includes arbitrary script code. In particular, the username URL parameter does not filter variations of HTML tags. A legitimate user who browses the malicious link will have the attacker-supplied script code executed in their browser, in their context of the website running the vulnerable software.
This may enable an attacker to steal cookie-based authentication credentials from the legitimate user.
Exploit / POC
Powie PForum Username Cross-Site Scripting Vulnerability
The following example was provided:
http://www.server.com/pforum/edituser.php?boardid=&agree=1
&username=%3Cscript%3Ealert(document.cookie)%3C/script%3E
&nickname=test&[email protected]&pwd=test&pwd2=test&filled=1
The following example was provided:
http://www.server.com/pforum/edituser.php?boardid=&agree=1
&username=%3Cscript%3Ealert(document.cookie)%3C/script%3E
&nickname=test&[email protected]&pwd=test&pwd2=test&filled=1
Solution / Fix
Powie PForum Username Cross-Site Scripting Vulnerability
Solution:
This issue has been addressed in version 1.15 of the software.
Powie PForum 1.11
Powie PForum 1.12
Powie PForum 1.13
Powie PForum 1.14
Solution:
This issue has been addressed in version 1.15 of the software.
Powie PForum 1.11
-
Powie pforum_115.zip
http://www.powie.de/pm/pmagic.php?pmagic=pforum
Powie PForum 1.12
-
Powie pforum_115.zip
http://www.powie.de/pm/pmagic.php?pmagic=pforum
Powie PForum 1.13
-
Powie pforum_115.zip
http://www.powie.de/pm/pmagic.php?pmagic=pforum
Powie PForum 1.14
-
Powie pforum_115.zip
http://www.powie.de/pm/pmagic.php?pmagic=pforum