ignore security and it'll go away

Sphinix Mobile Web Server U3 3.1.2.47 Cross Site Scripting

Sphinix Mobile Web Server U3 3.1.2.47 Cross Site Scripting
Posted Feb 3, 2012
Authored by Prabhu S Angadi | Site secpod.com

Sphinix Mobile Web Server version U3 3.1.2.47 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss
MD5 | 78307a0ee83a8ca8fd06ed6beced3ab9

Sphinix Mobile Web Server U3 3.1.2.47 Cross Site Scripting

Change Mirror Download
##############################################################################
#
# Title : Sphinix Mobile Web Server Multiple Persistent XSS Vulnerabilities
# Author : Prabhu S Angadi SecPod Technologies (www.secpod.com)
# Vendor : http://www.sphinx-soft.com/MWS/index.html
# Advisory : http://secpod.org/blog/?p=453
# http://secpod.org/advisories/SecPod_SPHINX_SOFT_Mobile_Web_Server_Mul_Persistence_XSS_Vulns.txt
# Software : Mobile Web Server U3 3.1.2.47
# Date : 01/08/2012
#
###############################################################################

SecPod ID: 1027 23/08/2011 Issue Discovered
20/01/2012 Vendor Notified
No Response
01/02/2012 Advisory Released


Class: Cross-Site Scripting (Persistent) Severity: Medium


Overview:
---------
Sphinx Software Mobile Web Server is prone to multiple persistent Cross Site
Scripting vulnerabilities.


Technical Description:
----------------------
Input passed via the 'comment' to 1)/Blog/MyFirstBlog.txt,
2)/Blog/AboutSomething.txt pages are not properly verified, which allows remote
attackers to inject arbitrary script code.


Impact:
--------
Successful exploitation could allow remote attackers to execute malicious
scripts and steal sensitive data.


Affected Software:
------------------
Mobile Web Server U3 3.1.2.47


Tested on:
-----------
Mobile Web Server U3 3.1.2.47 on Windows XP SP2.


References:
-----------
http://secpod.org/blog/?p=453


Proof of Concept:
----------------
1) /Blog/MyFirstBlog.txt?comment=<script>alert(1234)</script>&submit=Add+Comment


2) /Blog/AboutSomething.txt?comment=<script>alert(1234)</script>&submit=Add+Comment


Vendor URL:
----------------
http://www.sphinx-soft.com/MWS/index.html


Solution:
----------
Not available


Risk Factor:
-------------
CVSS Score Report:
ACCESS_VECTOR = NETWORK
ACCESS_COMPLEXITY = LOW
AUTHENTICATION = NOT_REQUIRED
CONFIDENTIALITY_IMPACT = PARTIAL
INTEGRITY_IMPACT = PARTIAL
AVAILABILITY_IMPACT = NONE
EXPLOITABILITY = PROOF_OF_CONCEPT
REMEDIATION_LEVEL = UNAVAILABLE
REPORT_CONFIDENCE = CONFIRMED
CVSS Base Score = 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N)

Credits:
--------
Prabhu S Angadi of SecPod Technologies has been credited with the discovery of this
vulnerability.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close