what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

eBuddy Web Messenger Cross Site Scripting

eBuddy Web Messenger Cross Site Scripting
Posted Sep 1, 2011
Authored by Russian Federation

eBuddy Web Messenger suffers from a cross site scripting vulnerability.

tags | exploit, web, xss
SHA-256 | 77b4fe175a400f550ca56f490b3da9cd7a692adb0823cd175fed9a0e611b28bb

eBuddy Web Messenger Cross Site Scripting

Change Mirror Download
           ################################################################################
########### \ \ / /(_) _ __ | |_ _ _ __ _ | | ###############
########### \ \ / / | || '__|| __|| | | | / _` || | ###############
########### \ V / | || | | |_ | |_| || (_| || | ###############
########### \_/ |_||_| \__| \__,_| \__,_||_| ###############
########### ###############
########### _ _ ###############
###########| | _ _ _ __ ___ (_) _ __ ___ _ _ ___ ###############
###########| | | | | || '_ ` _ \ | || '_ \ / _ \ | | | |/ __| ###############
###########| |___| |_| || | | | | || || | | || (_) || |_| |\__ \ ###############
###########|_____|\__,_||_| |_| |_||_||_| |_| \___/ \__,_||___/ ###############
################################################################################
warv0x, krypt0n, Russian Fedration, sol@ris(s0lar), yoadee



P.S: Shoutout to Xpired.


Author: Russian Fedration
Date: 31.08.2011
Version: Works with latest eBuddy Web Messenger. (as of September 2011)
Vulnerability: Persistent XSS
In-depth detail: eBuddy Web Messenger suffers from an encoded-

Persistent XSS vulnerability in the messaging function. (while sending

A message with embedded code to another authorized user in eBuddy Web

Messenger)



Exploit example:

Plain XSS (Not going to store, nor execute)

<script>alert('eBuddy Persistent XSS');</script>



Encoded

text=%3Cscript%3Ealert%28'eBuddy%20Persistent%20XSS'%29%3C/script%3E

Images:



[*] The attacker sends the encoded embedded code in an IM message. (Image 1)

Image 1;
http://i.minus.com/iLkBc67tzK5N.png


[*] The victim receives the message with the encoded embedded code and it executes on the victims browser.(Image 2)

Image 2;
http://img594.imageshack.us/img594/6485/ebuddy.png



###########################################################################################################

Note:

We're not going to show examples of malicious use to avoid the usage of

fame hungry kidiots. If you're creative, the universe is the limit. :)

###############################################################################################################
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close