exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Team Johnlong RaidenTunes 2.1.1 Cross Site Scripting

Team Johnlong RaidenTunes 2.1.1 Cross Site Scripting
Posted Aug 5, 2010
Authored by LiquidWorm | Site zeroscience.mk

Team Johnlong RaidenTunes version 2.1.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 4199949d35c67667cd038d30a7f4e8a72521e296137d729dadf966fb082dfe7a

Team Johnlong RaidenTunes 2.1.1 Cross Site Scripting

Change Mirror Download



Title: Team Johnlong RaidenTunes 2.1.1 Remote Cross-Site Scripting Vulnerability



Vendor: RaidenFTPDteam / Team Johnlong Software

Product Web Page: http://www.raidentunes.com

Summary: RaidenTunes is a Web server based + application software that
allows You to setup an online music server quickly. It can scan the music
folders in Your PC and organize them into a database, allowing users to
connect to this server and browser/search and listen to the music easily.
Interaction between users is also possible with built in message board for
albums.

Desc: RaidenTunes 2.1.1 suffers from a Cross-Site Scripting (XSS) vulnerability
caused by improper validation of user-supplied input by the music_out.php
script thru "p" param. A remote attacker could exploit this vulnerability
to execute script in a victim's Web browser within the security context of
the hosting Web site, allowing the attacker to steal the victim's cookie-based
authentication credentials.

Affected Version: 2.1.1

Tested On: Microsoft Windows XP Professional SP3 (English)


Vendor Status: [02.08.2010] - Vulnerability discovered.
[02.08.2010] - Initial contact with the vendor.
[02.08.2010] - Vendor replied asking for details.
[02.08.2010] - Sent PoC to vendor.
[02.08.2010] - Vendor confirms vulnerability.
[04.08.2010] - Vendor releases version 2.1.2 to address this issue.
[04.08.2010] - Public advisory released.


Zero Science Lab Advisory ID: ZSL-2010-4947
Advisory URL: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4947.php


Vulnerability Discovered By: Gjoko 'LiquidWorm' Krstic
liquidworm gmail com

Zero Science Lab
http://www.zeroscience.mk

02.08.2010



Proof Of Concept:

http://192.168.17.19/music_out.php?p=29%27%3Cscript%3Ealert%28document.cookie%29%3C/script%3E
http://192.168.17.19/music_out.php?p=%27%3Cscript%3Ealert%28document.cookie%29%3C/script%3E
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close