InterN0T - Advisories Advisories that are found by members of InterN0T.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack (3) Thread Tools Display Modes
  3 links from elsewhere to this Post. Click to view. #1  
Old 12th June 2009, 22:02
MaXe's Avatar
The Founder
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 2,714
Blog Entries: 31
Rep Power: 10
Reputation: 146
MaXe will become a Token soonMaXe will become a Token soon
[InterN0T] transLucid 1.75 - Multiple Vulnerabilities

transLucid - Cross Site Scripting and HTML Injection Vulnerabilities

Version Affected: 1.75 (newest)

Info: transLucidonline is the easy website publishing system with
which anyone can create and maintain web content, in multiple
languages and based on a growing list of ready-made, professional layouts.

Credits: InterN0T (macd3v and MaXe)

External Links:
http://www.pantha.net/


-:: The Advisory ::-
Quote:
Vulnerable Function / ID Calls:
NodeID & action (vulnerable in both admin and public panels)

Cross Site Scripting: (anyone - this was tested with public mode on)
1) http://[HOST]/translucid/transLucid_175/?NodeID="><script>alert(0)</script>
2) http://[HOST]/translucid/transLucid_175/?action="><script>alert(0)</script> (found by macd3v)
3) http://[HOST]/translucid/transLucid_175/?admin_section=1&NodeID="><script>alert(0)</script>
-- Number 3 might require moderator or administrative access if public mode is not turned on.

HTML Injection:
- If public mode is on / chosen, editing the following page-fields will result in script execution: Title & Url

Adding a new page can result in HTML Injection too. (Parent & Child pages were fully tested.)

Affected Sites by HTML Injection: (there will most likely be a lot more.)
http://[HOST]/translucid/transLucid_175/?action=switchto_editmode
-- In the admin panel "> needs to be prepended most likely in order to execute the injection.
--=-- Switching the theme to Developer can result in HTML Injection if there is any injected.
-:: Solution ::-
Regular expression match and / or bad characters conversion rocks!

Conclusion:
Easy to install and use, but the code should have been reviewed long ago.

Disclosure Information:
- Vulnerabilities found, researched and confirmed between 5th to 10th June.
- Advisory finished and published on InterN0T the XXth June.
- Vendor and Buqtraq (SecurityFocus) contacted the XXth June.


All of the best,
MaXe
__________________
Code:
                                ____/____\_________________
                      \|/      | OMG IT'S TEH LEET STORY!! |
    /*\         /\    -*-      |______  ________/\_________|
   // \\       /  \   /|\        /    \/    \  /  \
  /// \\\     /    \            /            \/    \
   // \\     /      \          /      \o/     \     \
    | |     /        \        /        |       \     \
 ___| |____/          \______/________/ \_______\_____\_________
          /     o      \
               #"=-
               /\
 __________________________________________________________
    On a mission, to find the lost member of Teh Unkwon.. 
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://forum.intern0t.net/intern0t-advisories/1122-intern0t-translucid-1-75-multiple-vulnerabilities.html
Posted By For Type Date
US-CERT Cyber Security Bulletin SB09-180 -- Vulnerability Summary for the Week of June 22, 2009 This thread Refback 30th January 2010 20:56
US-CERT Cyber Security Bulletin SB09-180 -- Vulnerability Summary for the Week of June 22, 2009 This thread Refback 29th June 2009 17:48
transLucid Script Insertion and Cross-Site Scripting - Secunia Advisories - Vulnerability Information - Secunia.com This thread Refback 15th June 2009 16:10

Similar Threads
Thread Thread Starter Forum Replies Last Post
[InterN0T] AMember 3.1.7 - Multiple Vulnerabilities MaXe InterN0T - Advisories 11 27th September 2009 19:09
[InterN0T] TBDev 01-01-2008 - Multiple Vulnerabilities MaXe InterN0T - Advisories 0 12th June 2009 21:58
[InterN0T] SkyBlueCanvas 1.1 r237 - Multiple Vulnerabilities MaXe InterN0T - Advisories 0 12th June 2009 21:51
[InterN0T] Pivot 1.40.4-7 - Multiple Vulnerabilities MaXe InterN0T - Advisories 0 12th June 2009 21:47
[intern0t] TransLucid XSS macd3v Exploits, Vulnerabilities & PoCs 5 12th June 2009 11:58


All times are GMT +2. The time now is 09:56.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1