|
|
|
|
|
Enviado por OeX el Sa, 18/02/2006 - 12:11.
|
New eVuln Advisory: My Blog BBCode XSS Vulnerabilities http://evuln.com/vulns/79/summary.html
--------------------Summary---------------- eVuln ID: EV0079 Software: My Blog Sowtware's Web Site: http://fuzzymonkey.net/cgi-bin/download.cgi?file=blog Versions: My Blog 1.63 Critical Level: Harmless Type: Cross-Site Scripting Class: Remote Status: Patched Exploit: Available Solution: Available Discovered by: Aliaksandr Hartsuyeu (eVuln.com)
-----------------Description--------------- Arbitrary script code insertion is possible in BBcode [url] and [img] tags.
--------------Exploit---------------------- Available at: http://evuln.com/vulns/79/exploit.html
BBcode Cross-Site Scripting Examples:
[img]javascript:alert(123)[/img]
[url=javascript:alert(123)]Click me[/url]
--------------Solution--------------------- Install new version: 1.65
Or
Replace BBCode.pm module by new one from
http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz
--------------Credit----------------------- Discovered by: Aliaksandr Hartsuyeu (eVuln.com)
Regards, Aliaksandr Hartsuyeu http://evuln.com
|
|
|
|
|
|
Enviar un comentario nuevo