Yoono Desktop add-on version 1.8.16 suffers from a cross site scripting vulnerability.
bf747ffeab90b65e5dcef68382ab8cd6 TITLE: Yoono Desktop Application Persistent XSS
vendor: Yoono
Version: 1.8.16
Impact: Persistent XSS
Software Link: available in yoono site
Author: r007k17-w
Email: n4gb07@gmail.com
Twitter: http://twitter.com/#!/r007k17w
My blog: http://shadowrootkit.wordpress.com/
-------------------------------------------------------------------------------------------------------------------------------------------
DEMO:
1.From yonoo Apps Login with any account(say google).
2.Online friend list is opened
3.Click 'friends' link just below the status field.
4.Pop up window 'Add friends' is seen.
5.Input random email-id,eg: qwerty@xyz.com and Create a group
by selecting
field.(drop down)
6.Now in the 'create' field
POST DATA:"><iframe src="JavaScript:alert('XSS');></iframe>
Tested On:
Win7 Ultimate(6.1,build 7600)
Solution: Input sanitization,Upgrade to next version
---------------------------------------------------------------------------------------------------------------------------------------------
gr33t1ngs to s1d3-3ff3cts,L0rd CrUs4d3r,3ps1lonl4mbd4,A1-w1n6( N17|<
),1nJ3ct0rs
------------------------------------------------------------------------------------------
-----------
Comments (2)
Hi there,
Thanks for finding this, we'll fix it as fast as possible.
If I may suggest, it would have been great to contact us, preferably before making this public, to give us a chance to fix it first, as is usual with security issues.
best regards,
Xavier
2012-02-17 13:56:22 UTC | Permalink | Reply
Hi, this was fixed on Friday, new release available on our website.
2012-02-20 09:47:17 UTC | Permalink | Reply