the internet's safety

atomphotoblog-xss.txt

atomphotoblog-xss.txt
Posted Jun 10, 2007
Site serapis.net

Atom Photoblog versions 1.0.9 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 315119dff9a9aea902c3c625f15cb8ed

atomphotoblog-xss.txt

Change Mirror Download
Application: Atom Photoblog
Web Site: http://atomphotoblog.ilenvo.de/
Versions: 1.0.9 and below
Platform: linux, windows, freebsd, sun
Bug: Cross site Scripting (XSS)
Fix Available: Yes
Advisory File: http://www.secvsn.com/content/Advisories/sr-060607-atomphotoblog.html

-------------------------------------------------------

1) Introduction
2) Bug
3) The Code
4) Fix
5) About Serapis
6) Disclaimer

===========
1) Introduction
===========

"photo-blog is a blog with the intention to publish photos chronologically.
This script is dedicated to exactly this task - without any additional juggling.
The word "Atom" in the title indicates just this fact -
we have created a kernel of such a blog, there's nothing missing,
but also, there's nothing nagging. Thus, these scripts perform extremely good."

======
2) Bug
======

Cross Site Scripting.

===============
3) Proof of concept.
===============

example:

http://site.com/atomphotoblog/atomPhotoBlog.php?do=index&tag=<ScRiPt%20%0a%0d>alert(1566213939)%3B</ScRiPt>

=====
4) Fix
=====

the Author was notified and released fixed version (1.0.9.1).
Quick and Quality response from the Vendor site.
http://sourceforge.net/project/showfiles.php?group_id=186464

============
5) About Serapis.net
============

www.Serapis.net - is a portal dedicated to monitoring web defacements,
tracking defacements around the world 24/7.
serapis is the R&D Site of Secure Vision.

==========
6) Disclaimer
==========

The information within this paper may change without notice.
Use of this information constitutes acceptance for use in an AS IS condition.
There are NO warranties with regard to this information.
In no event shall the author be liable for any damages whatsoever arising out
of or in connection with the use or spread of this information.
Any use of this information is at the user's own risk.

http://www.serapis.net - Web Site.
http://calima.serapis.net/blogs/ - Web defacements blog.
http://www.secvsn.com - SecureVision Web Site

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close