ArrowChat Local File Include and Cross Site Scripting Vulnerabilities
BID:57671
Info
ArrowChat Local File Include and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 57671 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2013 12:00AM |
| Updated: | Feb 04 2013 12:00AM |
| Credit: | Kallimero |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ArrowChat Local File Include and Cross Site Scripting Vulnerabilities
ArrowChat is prone to a local file-include vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the web server process.
ArrowChat 1.5.61 is vulnerable; other versions may also be affected.
ArrowChat is prone to a local file-include vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the web server process.
ArrowChat 1.5.61 is vulnerable; other versions may also be affected.
Exploit / POC
ArrowChat Local File Include and Cross Site Scripting Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/[path]/external.php?lang=../path/to/file%00&type=djs
http://www.example.com/[path]/admin/layout/pages_general.php/'"/><script>alert(1);</script>
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/[path]/external.php?lang=../path/to/file%00&type=djs
http://www.example.com/[path]/admin/layout/pages_general.php/'"/><script>alert(1);</script>
Solution / Fix
ArrowChat Local File Include and Cross Site Scripting Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ArrowChat Local File Include and Cross Site Scripting Vulnerabilities
References:
References: