what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

articlelive-xss.txt

articlelive-xss.txt
Posted May 13, 2008
Authored by SkyOut | Site wired-security.net

Interspire ArticleLive NX is vulnerable to a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 600f5af39b27695784b428bdccc38aba01ce7140cb248bfb9c88e28d8ff66982

articlelive-xss.txt

Change Mirror Download
____________________________________________________________________________
____________________________________________________________________________

01010111 01001001 01010010 01000101 01000100 01010011 ->
01000101 01000011 01010101 01010010 01001001 01010100 ->
01011001

____________________________________________________________________________
ADVISORY: INTERSPIRE ARTICLELIVE NX XSS
____________________________________________________________________________

_____________________
|| 0x00: ABOUT ME
|| 0x01: DATELINE
|| 0x02: INFORMATION
|| 0x03: EXPLOITATION
|| 0x04: RISK LEVEL

____________________________________________________________
____________________________________________________________

_________________
|| 0x00: ABOUT ME

Author: SkyOut
Date: May 2008
Website: http://wired-security.net/

_________________
|| 0x01: DATELINE

2007-05-09: Bug found
2007-05-10: Advisory released

____________________
|| 0x02: INFORMATION

The website of the product, located at http://www.interspire.com/articlelive/,
says the following about their tool:

"ArticleLive is a complete content management package that lets you start,
maintain and grow your own article, news and/or blog site. It includes
professionally designed, CSS-driven website templates which are easy to
customize to your liking."

So it is a news script. Now the problem occurrs due to a badly filtering search
engine! You can easily escape the value="" parameter and inject JavaScript.

_____________________
|| 0x03: EXPLOITATION

To test this, try a demo, they provide it for free:
http://www.interspire.com/articlelive/demo.php

Then go the site including the search field, it is located here:
http://websitepublisher.interspire-demo.com/demo_<some number>/search

Escape the given string with "> first and then make your JavaScript!

E.g.: "><script>alert("XSS");</script>

Results in:

__________________________________________
| X |
|________________________________________|
| |
| |
| ^ |
| / \ |
| / | \ XSS |
| / . \ |
| ------- |
| ______ |
| | OK | |
| ------ |
|________________________________________|

___________________
|| 0x04: RISK LEVEL

- LOW - (1/3) -

<!> Happy Hacking <!>

____________________________________________________________________________
____________________________________________________________________________

EOF
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close