exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

dotclear 2.8.1 Cross Site Scripting

dotclear 2.8.1 Cross Site Scripting
Posted Nov 16, 2015
Authored by Tim Coen | Site curesec.com

dotclear version 2.8.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f7069d8f699466eafd8721698222a6c4a8e0e2de33c5167d42ccadd7ceda4dc0

dotclear 2.8.1 Cross Site Scripting

Change Mirror Download
Security Advisory - Curesec Research Team

1. Introduction

Affected Product: dotclear 2.8.1
Fixed in: 2.8.2
Fixed Version Link: http://download.dotclear.org/latest.zip
Vendor Website: http://dotclear.org/
Vulnerability Type: XSS
Remote Exploitable: Yes
Reported to vendor: 10/02/2015
Disclosed to public: 11/13/2015
Release mode: Coordinated release
CVE: n/a
Credits Tim Coen of Curesec GmbH

2. Overview

CVSS

Low 2.6 AV:N/AC:H/Au:N/C:N/I:P/A:N

Description

The Comment author name is echoed inside the value attribute of an input tag
when viewing the list of all comments for that author. Quotes are not encoded,
which allows for the addition of further attributes to the tag.

The field is hidden, so onfocus or similar do not work, and the length of the
name is limited, which makes an actual exploitation unlikely. Still, with older
browser an attacker might try to inject a style attribute which may lead to
XSS.

3. Proof of Concept


1. Create comment with author name
" newattribute="value
2. Visit
http://localhost/dotclear/admin/comments.php?n=30&status=&sortby=comment_dt&order=desc&author=%22+newattribute%3D%22value
3. The result will be:
<input type="hidden" name="author" value="" newattribute="value" />

4. Solution

To mitigate this issue please upgrade at least to version 2.8.2:

http://download.dotclear.org/latest.zip

Please note that a newer version might already be available.

5. Report Timeline

10/02/2015 Informed Vendor
10/25/2015 Vendor releases fix
11/13/2015 Disclosed to public


Blog Reference:
http://blog.curesec.com/article/blog/dotclear-281-XSS-94.html


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close