what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

os2a_1007.txt

os2a_1007.txt
Posted Sep 14, 2006
Authored by NR Nandini

Multiple cross site scripting vulnerabilities have been identified in SoftComplex Inc.'s PHP Event Calendar version 1.5.1. Prior versions may also be susceptible.

tags | exploit, php, vulnerability, xss
SHA-256 | fa612026fe79ef3bb592170199626740daa97b46923fceb0bd732b41be574efd

os2a_1007.txt

Change Mirror Download
PHP Event Calendar Multiple Parameter Cross Site Scripting Vulnerability


OS2A ID: OS2A_1007 Status:
08/20/2006 Issue Discovered
09/06/2006 Reported to the Vendor
09/09/2006 Fixed by Vendor
09/13/2006 Advisory Released


Class: Cross Site Scripting Severity: Low


Overview:
---------
PHP Event Calendar is a reusable PHP script that extends a web site's
functionality with an event scheduler and/or news archive.
http://www.softcomplex.com/products/php_event_calendar/

Description:
------------
A cross-site scripting vulnerability exists in PHP Event Calendar, due to input
validation error in parameters tilte(ti), body(bi) and backgroung Image(cbgi)
in cl_files/index.php page when adding a new event.

Successful exploitation requires authentication.

Impact:
-------
An authenticated remote attacker could inject malicious HTML and script code in
other user's browser session within the security context of the affected site.

Affected Software(s):
---------------------
PHP Event Calendar 1.5.1 (prior versions may also be vulnerable)

Proof of Concept:
-----------------
http://www.yoursite.com/directory_where_you_installed_php_event_calendar/cl_files/index.php
Vulnerable fields: title field - ti
body field - bi
Backgroung Image - cbgi

Insert "<script>alert('XSS Vulnerable');</script>" in above field and click
"Add event".

CVSS Score Report:
-----------------
ACCESS_VECTOR = REMOTE
ACCESS_COMPLEXITY = LOW
AUTHENTICATION = REQUIRED
CONFIDENTIALITY_IMPACT = NONE
INTEGRITY_IMPACT = PARTIAL
AVAILABILITY_IMPACT = NONE
IMPACT_BIAS = INTEGRITY
EXPLOITABILITY = PROOF_OF_CONCEPT
REMEDIATION_LEVEL = OFFICIAL_FIX
REPORT_CONFIDENCE = CONFIRMED
CVSS Base Score = 2.1 (AV:R/AC:L/Au:R/C:N/I:P/A:N/B:I)
CVSS Temporal Score = 1.6
Risk factor = Low


Vendor Response:
---------------
"Attached is the version that blocks the use of the <script> in the
text of the event. We can't block use of HTML completely because many
users want to be able to use HTML for the event descriptions. The
events are managed in the password protected control panel so there
was no security threat even before the change was applied."


Solution:
---------

Update to the fixed version,
http://www.softcomplex.com/products/php_event_calendar/

Credits:
--------
NR Nandini of OS2A has been credited with the discovery of this vulnerability.
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close