what you don't know can hurt you

bloofoxCMS 0.3.5 Cross Site Scripting

bloofoxCMS 0.3.5 Cross Site Scripting
Posted Oct 31, 2012
Authored by Canberk BOLAT | Site netsparker.com

bloofoxCMS version 0.3.5 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
MD5 | 5c23259c73260b4e14a632d34f0365b9

bloofoxCMS 0.3.5 Cross Site Scripting

Change Mirror Download
Information
--------------------
Name : XSS Vulnerabilities in bloofoxCMS
Software : bloofoxCMS 0.3.5 and possibly below.
Vendor Homepage : http://www.bloofox.com
Vulnerability Type : Cross-Site Scripting
Severity : Critical
Researcher : Canberk Bolat
Advisory Reference : NS-12-015

Description
--------------------
bloofoxCMS is a free open source content management system (CMS).
bloofoxCMS is a small and easy to use CMS. It enables you to manage
websites and intranet sites on a very simple way. It is slim but also
flexible.

Details
--------------------
bloofoxCMS is affected by XSS vulnerabilities in version 0.3.5

http://example.com/index.php?'"--><script>alert(0x0004B3)</script>
http://example.com/index.php?search='"--><script>alert(0x0004B3)</script>
You can read the full article about Cross-Site Scripting from here:

Cross-site Scripting (XSS)
Solution
--------------------
The vendor fixed this vulnerability in the new version. Please see the
references.

Advisory Timeline
--------------------
23/01/2011 - First contact
25/02/2012 - Vulnerability Fixed
31/10/2012 - Advisory released

Credits
--------------------
It has been discovered on testing of Netsparker, Web Application Security
Scanner - http://www.mavitunasecurity.com/netsparker/.

References
--------------------
Vendor Url / Patch : http://www.bloofox.com/change_log.24.html
MSL Advisory Link :
http://www.mavitunasecurity.com/xss-vulnerabilities-in-bloofoxcms/
Netsparker Advisories :
http://www.mavitunasecurity.com/netsparker-advisories/

About Netsparker
--------------------
Netsparker® can find and report security issues such as SQL Injection and
Cross-site Scripting (XSS) in all web applications regardless of the
platform and the technology they are built on. Netsparker's unique
detection and exploitation techniques allows it to be dead accurate in
reporting hence it's the first and the only False Positive Free web
application security scanner.

--
Netsparker Advisories, <advisories@mavitunasecurity.com>
Homepage, http://www.mavitunasecurity.com/netsparker-advisories/

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

February 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    1 Files
  • 2
    Feb 2nd
    2 Files
  • 3
    Feb 3rd
    17 Files
  • 4
    Feb 4th
    15 Files
  • 5
    Feb 5th
    24 Files
  • 6
    Feb 6th
    16 Files
  • 7
    Feb 7th
    19 Files
  • 8
    Feb 8th
    2 Files
  • 9
    Feb 9th
    2 Files
  • 10
    Feb 10th
    15 Files
  • 11
    Feb 11th
    20 Files
  • 12
    Feb 12th
    16 Files
  • 13
    Feb 13th
    19 Files
  • 14
    Feb 14th
    17 Files
  • 15
    Feb 15th
    4 Files
  • 16
    Feb 16th
    4 Files
  • 17
    Feb 17th
    34 Files
  • 18
    Feb 18th
    15 Files
  • 19
    Feb 19th
    20 Files
  • 20
    Feb 20th
    34 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close