BBCaffe Input Validation Hole in E-mail Field Permits Cross-Site Scripting Attacks
|
|
SecurityTracker Alert ID: 1014733
|
|
SecurityTracker URL: http://securitytracker.com/id?1014733
|
|
CVE Reference: CVE-2005-2653
(Links to External Site)
|
Updated: Jun 8 2008
|
Original Entry Date: Aug 18 2005
|
Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information
|
Exploit Included: Yes
|
Version(s): 2.0
|
Description: rgod reported a vulnerability in BBCaffe. A remote user can conduct cross-site scripting attacks.
Several scripts do not properly filter HTML code from user-supplied input before displaying the input. A remote user can submit
a message with a specially crafted e-mail field. Then, when the message is viewed by a target user, arbitrary scripting code to
be executed by the target user's browser. The code will originate from the site running the BBCaffe software and will run in the
security context of that site. As a result, the code will be able to access the target user's cookies (including authentication
cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take
actions on the site acting as the target user.
A demonstration exploit e-mail value is provided:
'><script>alert(document.cookie)</script>
|
Impact: A remote user can access the target user's cookies (including authentication cookies), if any, associated with the site running the
BBCaffe software, access data recently submitted by the target user via web form to the site, or take actions on the site acting
as the target user.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.developertutorials.com/dtscripts/view.php?id=2576&vt=0 (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: "retrogod@aliceposta.it" <retrogod@aliceposta.it>
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 18 Aug 2005 11:04:21 +0200 (ora legale Europa occidentale)
From: "retrogod@aliceposta.it" <retrogod@aliceposta.it>
Subject: BBCaffe 2.0 cross site scripting poc
|
BBCaffe 2.0 cross site scripting poc
description: BBcaffe 2.0 is a fast, simple, easy and efficient bulletin board or
message board program built in PHP/mySQL. Features include: posting, replying,
deleting, editing, searching messages, sending notification email(s) , full templating.
author site: http://www.developertutorials.com
download page: http://www.developertutorials.com/dtscripts/view.php?id=2576&vt=0
xss:
a user can submit a message, with an e-mail like this, ;) :
'><script>alert(document.cookie)</script>
or insert HTML code to deface board
rgod
site: http://rgod.altervista.org
email: retrogod@aliceposta.it
_____________________________________________________________________
FREE Emoticons for your email! Click Here!
|
|