exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

eBuddy Web Messenger Cross Site Scripting

eBuddy Web Messenger Cross Site Scripting
Posted Sep 1, 2011
Authored by Russian Federation

eBuddy Web Messenger suffers from a cross site scripting vulnerability.

tags | exploit, web, xss
SHA-256 | 77b4fe175a400f550ca56f490b3da9cd7a692adb0823cd175fed9a0e611b28bb

eBuddy Web Messenger Cross Site Scripting

Change Mirror Download
           ################################################################################
########### \ \ / /(_) _ __ | |_ _ _ __ _ | | ###############
########### \ \ / / | || '__|| __|| | | | / _` || | ###############
########### \ V / | || | | |_ | |_| || (_| || | ###############
########### \_/ |_||_| \__| \__,_| \__,_||_| ###############
########### ###############
########### _ _ ###############
###########| | _ _ _ __ ___ (_) _ __ ___ _ _ ___ ###############
###########| | | | | || '_ ` _ \ | || '_ \ / _ \ | | | |/ __| ###############
###########| |___| |_| || | | | | || || | | || (_) || |_| |\__ \ ###############
###########|_____|\__,_||_| |_| |_||_||_| |_| \___/ \__,_||___/ ###############
################################################################################
warv0x, krypt0n, Russian Fedration, sol@ris(s0lar), yoadee



P.S: Shoutout to Xpired.


Author: Russian Fedration
Date: 31.08.2011
Version: Works with latest eBuddy Web Messenger. (as of September 2011)
Vulnerability: Persistent XSS
In-depth detail: eBuddy Web Messenger suffers from an encoded-

Persistent XSS vulnerability in the messaging function. (while sending

A message with embedded code to another authorized user in eBuddy Web

Messenger)



Exploit example:

Plain XSS (Not going to store, nor execute)

<script>alert('eBuddy Persistent XSS');</script>



Encoded

text=%3Cscript%3Ealert%28'eBuddy%20Persistent%20XSS'%29%3C/script%3E

Images:



[*] The attacker sends the encoded embedded code in an IM message. (Image 1)

Image 1;
http://i.minus.com/iLkBc67tzK5N.png


[*] The victim receives the message with the encoded embedded code and it executes on the victims browser.(Image 2)

Image 2;
http://img594.imageshack.us/img594/6485/ebuddy.png



###########################################################################################################

Note:

We're not going to show examples of malicious use to avoid the usage of

fame hungry kidiots. If you're creative, the universe is the limit. :)

###############################################################################################################
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close