Re: [VulnWatch] XSS & Header Injection in Drupal and vBulletin
"Morning Wood" <[email protected]> Wed, 30 Nov 2005 17:45:16 -0800
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.news.securitytracker,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <[email protected]> |
oh, like i mentioned a few monts ago... nice ----- Original Message ----- From: "Paul Laudanski" <[email protected]> To: <[email protected]>; <[email protected]>; <[email protected]>; <[email protected]>; <[email protected]>; <[email protected]>; <[email protected]> Sent: Wednesday, November 30, 2005 4:34 PM Subject: [VulnWatch] XSS & Header Injection in Drupal and vBulletin > A fake image header with actual html body content was able to get past > phpbb's input validation. An exploit was issued for phpbb a month ago and > that sparked me to check some other webapps. > > vbulletin 3.5.0 forum file attachments did not sanitize against this, as a > result Jelsoft quickly issued release 3.5.1 as a fix. Other branches were > also fixed up to 3.0.10 and 2.3.8. > > http://www.vbulletin.com/forum/showthread.php?postid=1002384 > > "The first flaw is in Microsoft Internet Explorer. It affects vBulletin > image uploads and potentially opens a cross-site-scripting exploit. It has > affected many web-based applications that allow image uploads, including > phpBB and Hotmail. Although a fix from Microsoft would be preferable, we > have implemented a work-around in all three branches of vBulletin to > prevent the Internet Explorer flaw from being exploited." > > drupal 4.6.3 was also tested and found to be vulnerable as well. > > http://drupal.org/node/39355 > > "Paul Laudanski informed us that it's possible to attach files that are > able to run Javascript under Internet Explorer. > > Further investigation of the problem revealed that the same method can be > used to inject arbitrary HTTP headers." > > Subsequently, all branches were fixed up to: 4.5.6, and 4.6.4. However, > PHP 4.3.0 is also required in this solution. > > Credit: CastleCops.com > -- > Paul Laudanski, Microsoft MVP Windows-Security > [de] http://de.castlecops.com > [en] http://castlecops.com > [wiki] http://wiki.castlecops.com > [family] http://cuddlesnkisses.com > >