what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

TISA2007-04-Public.txt

TISA2007-04-Public.txt
Posted Aug 8, 2007
Authored by Edi Strosar | Site teamintell.com

DVD Rental System version 5.1 suffers from cross site scripting and cross site request forgery vulnerabilities.

tags | advisory, vulnerability, xss, csrf
SHA-256 | f1dd1cc1119f7a2f434fb01e50ea068449fb1e941c2499592b9bbfd2032195ba

TISA2007-04-Public.txt

Change Mirror Download

=========================================================================
TeamIntell Security Advisory TISA2007-04-Public
-------------------------------------------------------------------------
DVD Rental System multiple XSS and CSRF vulnerabilities
=========================================================================


Release Date: 02.08.2007
Severity: Less critical
Impact: Cross Site Scripting (XSS)
Cross Site Request Forgery (CSRF)
Status: Official patch available
Software: DVD Rental System 5.1 (DRS)
Vendor: http://www.dvdrentalsystem.com/
Disclosed: Edi Strosar (TeamIntell)


Description:
============

DRS, an online DVD rental application, is vulnerable to
multiple XSS and CSRF attacks. Proof of concept will not
be publicly released.


Details:
========

TeamIntell discovered multiple vulnerabilities in online
DVD Rental System, which can be exploited by malicious
users to conduct cross-site scripting[1] and cross-site
request forgery[2] attacks:

[1] DRS does not properly sanitize users supplied data
before sending it to clients. This can be exploited to
execute arbitrary HTML and script code in a user's browser
session in context of an affected site.

[2] The script index.php allows users to perform certain
actions via HTTP requests without performing validity
checks to verify the request. This can be exploited to
modify users's data or cancel subscription permanently.

Note: in some cases CSRF attacks could be site specific.
TeamIntell developed working PoC that affects users of one
among DVD Rental System's business partners.

The vulnerabilities are confirmed in DVD Rental System
version 5.1. Other versions may be affected.


Solution:
=========

Vendor has reported that the DVD Rental System scripts are
updated and patched. Customers should contact the vendor
for details.


References:
===========

http://en.wikipedia.org/wiki/XSS
http://en.wikipedia.org/wiki/Cross-site_request_forgery


Timeline:
=========

20.07.2007 - vulnerabilities discovered
21.07.2007 - vendor informed
01.08.2007 - vendor reports that the scripts are updated
and patched
02.08.2007 - public disclosure


Contact:
========

Maldin d.o.o.
Trzaska cesta 2
1000 Ljubljana - SI

tel: +386 (0)590 70 170
fax: +386 (0)590 70 177
gsm: +386 (0)31 816 400
web: www.teamintell.com
e-mail: info@teamintell.com


Disclaimer:
===========

The content of this report is purely informational and
meant for educational purposes only. Maldin d.o.o. shall
in no event be liable for any damage whatsoever, direct or
implied, arising from use or spread of this information.
Any use of information in this advisory is entirely at
user's own risk.

=========================================================================

Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    23 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close