eNdonesia Mod Parameter Cross-Site Scripting Vulnerability
BID:8506
Info
eNdonesia Mod Parameter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8506 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2003 12:00AM |
| Updated: | Aug 27 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Bahaa Naamneh. |
| Vulnerable: |
eNdonesia eNdonesia 8.3 eNdonesia eNdonesia 8.2 |
| Not Vulnerable: | |
Discussion
eNdonesia Mod Parameter Cross-Site Scripting Vulnerability
It has been reported that eNdonesia is prone to a cross-site scripting vulnerability that may allow a remote attacker to execute HTML or script code in a victim's browser. The issue reportedly exists in the mod.php script via the 'mod' URI parameter.
Successful exploitation may allow an attacker to steal cookie-based credentials from a user. Other attacks are possible as well.
It has been reported that eNdonesia is prone to a cross-site scripting vulnerability that may allow a remote attacker to execute HTML or script code in a victim's browser. The issue reportedly exists in the mod.php script via the 'mod' URI parameter.
Successful exploitation may allow an attacker to steal cookie-based credentials from a user. Other attacks are possible as well.
Exploit / POC
eNdonesia Mod Parameter Cross-Site Scripting Vulnerability
The following proof of concept examples are provided:
Version 8.2:
http://www.example.com/mod.php?mod=<evil_code>
Version 8.3:
http://www.example.com/mod.php?mod=%3Ch1%3Etest-nih-publisher&op=viewcat&cid=dudul
The following proof of concept examples are provided:
Version 8.2:
http://www.example.com/mod.php?mod=<evil_code>
Version 8.3:
http://www.example.com/mod.php?mod=%3Ch1%3Etest-nih-publisher&op=viewcat&cid=dudul