/---------------------------------------------------------\ | MF Gig Calendar Wordpress Plugin - Cross-Site Scripting | \---------------------------------------------------------/ Summary ======= MF Gig Calendar 0.9.2 is subject to a cross-site scripting vulnerability. The value of a generic parameter was not sufficiently sanitised before being written to the calendar page. An attacker could distribute a malicious URL that would trigger this vulnerability and potentially steal session cookies, redirect the user to a malicious URL or download malware onto their machine. CVE number: CVE-2012-4242 Impact: Medium Vendor homepage: http://wordpress.org/extend/plugins/mf-gig-calendar/ Vendor notified: 20/07/2012, 07/08/2012 Vendor response: No reply was received from the author Credit: Chris Cooper and Joseph Sheridan of ReactionIS (http://www.reactionis.co.uk/) This advisory is posted at: http://www.reactionpenetrationtesting.co.uk/mf-gig-calendar-xss.html Affected Products ======== ======== MF Gig Calendar 0.9.2. Other versions may be affected. Details ======= A generic parameter on the calendar page was found to be subject to a cross-site scripting vulnerability. It was possible to inject arbitrary Javascript into the URL as an additional parameter (following an '&'). This code is then passed into an anchor href parameter without sanitisation, and executed by the browser. Injecting the following Javascript code into a generic parameter on the calendar page will trigger the vulnerability, causing the page to return a Javascript alert box. "> --- Example 1 Request: +----------------- GET /wp/?page_id=2&"> HTTP/1.1 Host: 192.168.0.6 Referer: http://192.168.0.6/wp/?page_id=2&ytd=2012 Cookie: wordpress_test_cookie=WP+Cookie+check; wp-settings-1=hidetb%3D1%26editor%3Dtinymce; wp-settings-time-1=1342447051; PHPSESSID=ls61d5ov9vugrfhgu45urh4n55 --- Example 1 Response: +------------------ HTTP/1.1 200 OK Date: Tue, 17 Jul 2012 09:00:14 GMT Server: Apache X-Powered-By: PHP/5.3.8 X-Pingback: http://192.168.0.6/wp/xmlrpc.php Content-Length: 6835 Content-Type: text/html; charset=UTF-8 --- SNIP ---

Upcoming Events

Upcoming | Archive: =&ytd=2012">2012