<?xml version="1.0"?><rss version="2.0">
<channel>
  <title>H-Security Labs - Advisories category</title>
  <link>http://www.h-labs.org/blog/categories/6/</link>
  <description>Bilgi Güvenliği Laboratuvarları</description>
  <language>tr</language>
  <copyright>Oykun SATIŞ &amp;&amp; Mesut TİMUR</copyright>
  <lastBuildDate>Thu, 03 Jul 2008 07:02:00 GMT</lastBuildDate>
  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  <item>
    <title>Tikiwiki 1.9.8.3 tiki-special_chars.php XSS Vulnerability</title>
    <link>http://www.h-labs.org/blog/2007/12/24/tikiwiki_1_9_8_3_tiki_special_chars_php_xss_vulnerability.html</link>
    <description>
          &lt;p align=&#034;center&#034;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; H - Security Labs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;
Tikiwiki v1.9.8.3 Security Advisory&lt;br /&gt;
ID : HSEC#20072212&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;General Information&lt;br /&gt;
--------------------------&lt;br /&gt;
Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Tikiwiki 1.9.8.3&lt;br /&gt;
Vendor HomePage&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;a href=&#034;http://tikiwiki.org&#034;&gt;http://tikiwiki.org&lt;/a&gt;&lt;br /&gt;
Platforms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : PHP &amp;amp;&amp;amp; MySQL&lt;br /&gt;
Vulnerability Type&amp;nbsp;&amp;nbsp;&amp;nbsp; : Input Validation Error &lt;/p&gt;
&lt;p&gt;Timeline&lt;br /&gt;
-------------------------&lt;br /&gt;
17 December&amp;nbsp; 2007&amp;nbsp; -- Vendor Contacted&amp;nbsp; &lt;br /&gt;
19 December&amp;nbsp; 2007&amp;nbsp; -- Vendor Replied&lt;br /&gt;
22 December 2007&amp;nbsp; -- New Release&lt;br /&gt;
22 December 2007&amp;nbsp; -- Advisory Released &lt;/p&gt;
&lt;p&gt;What is TikiWiki&lt;br /&gt;
------------------------&lt;br /&gt;
Tikiwiki (Tiki) is your Groupware/CMS (Content Management System) solution. Tiki has the features you need:&lt;br /&gt;
Wikis (like Mediawiki), Forums (like phpBB) ,Blogs (like WordPress), Articles (like Digg), Image Gallery (like Flickr), Map Server (like Google Maps), Link Directory (like DMOZ), Translation and i18n (like Babel Fish), Free (LGPL) And much more... &lt;/p&gt;
&lt;p&gt;Vulnerability Overview&lt;br /&gt;
------------------------&lt;br /&gt;
The script is vulnerable to XSS attacks. &lt;/p&gt;
&lt;p&gt;Details About Vulnerability&lt;br /&gt;
------------------------&lt;br /&gt;
XSS Vulnerability (/tikiwiki/tiki-special_chars.php)&lt;br /&gt;
At the lines between 166-168 : &lt;br /&gt;
-----------------&lt;br /&gt;
&amp;nbsp; &amp;lt;input type=&amp;quot;button&amp;quot; class=&amp;quot;button&amp;quot;&lt;br /&gt;
onclick=&amp;quot;javascript:window.opener.document.getElementById(&#039;&amp;lt;?php &lt;/p&gt;
&lt;p&gt;print($_REQUEST[&amp;quot;area_name&amp;quot;]);?&amp;gt;&#039;).value=window.opener.document.getElementById(&#039;&amp;lt;?php print($_REQUEST[&amp;quot;area_name&amp;quot;]);?&amp;gt;&#039;).value+getElementById(&#039;spec&#039;).value;&amp;quot; &lt;br /&gt;
name=&amp;quot;ins&amp;quot; value=&amp;quot;ins&amp;quot; /&amp;gt;&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;input type=&amp;quot;button&amp;quot; class=&amp;quot;button&amp;quot;&lt;br /&gt;
----------------- &lt;/p&gt;
&lt;p&gt;You see that, there are two printing of &amp;quot;area_name&amp;quot; variable without properly sanitization.This causes reflected XSS vulnerability and If you set area_name variable to : &lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;, you can see it..&lt;br /&gt;
The attacker can succesfully launch XSS attacks with loading payload on to the URL area_name variable. &lt;/p&gt;
&lt;p&gt;Solution&lt;br /&gt;
-----------------------&lt;br /&gt;
Download the new release : Tikiwiki 1.9.9&lt;br /&gt;
from &lt;a href=&#034;http://sourceforge.net/project/showfiles.php?group_id=64258&amp;amp;package_id=112134&amp;amp;release_id=563456&#034;&gt;http://sourceforge.net/project/showfiles.php?group_id=64258&amp;amp;package_id=112134&amp;amp;release_id=563456&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Credits&lt;br /&gt;
-----------------------&lt;br /&gt;
The vulnerabilities found on 17 December&amp;nbsp; 2007&lt;br /&gt;
by Mesut Timur &amp;lt;mesut@h-labs.org&amp;gt;&lt;br /&gt;
H - Security Labs , &lt;a href=&#034;http://www.h-labs.org&#034;&gt;http://www.h-labs.org&lt;/a&gt;&lt;br /&gt;
Gebze Institue of Technology,Computer Engineering,&lt;a href=&#034;http://www.gyte.edu.tr&#034;&gt;http://www.gyte.edu.tr&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;References&lt;br /&gt;
-----------------------&lt;br /&gt;
Vendor Confirmation : &lt;a href=&#034;http://tikiwiki.org/ReleaseProcess199&#034;&gt;http://tikiwiki.org/ReleaseProcess199&lt;/a&gt;&lt;/p&gt;</description>
      <category>Advisories</category>
    <comments>http://www.h-labs.org/blog/2007/12/24/tikiwiki_1_9_8_3_tiki_special_chars_php_xss_vulnerability.html#comments</comments>
    <guid isPermaLink="true">http://www.h-labs.org/blog/2007/12/24/tikiwiki_1_9_8_3_tiki_special_chars_php_xss_vulnerability.html</guid>
    <pubDate>Mon, 24 Dec 2007 13:50:13 GMT</pubDate>
  </item>
  <item>
    <title>Falt4 CMS Security Report/Advisory</title>
    <link>http://www.h-labs.org/blog/2007/12/05/falt4_cms_security_report_advisory.html</link>
    <description>
          &lt;p align=&#034;center&#034;&gt;H - Security Labs &lt;br /&gt;
Falt4Extreme (RC4 10.9.2007) Security Report &lt;br /&gt;
ID : HSEC#20071012&lt;/p&gt;
&lt;p&gt;General Information &lt;br /&gt;
-------------------------- &lt;br /&gt;
Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Falt4Extreme CMS (RC4 10.9.2007) &lt;br /&gt;
Vendor HomePage&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;a href=&#034;http://sourceforge.net/projects/falt4/&#034;&gt;http://sourceforge.net/projects/falt4/&lt;/a&gt; &lt;br /&gt;
Platforms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : PHP &amp;amp;&amp;amp; MySQL &lt;br /&gt;
Vulnerability Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Input Validation Errors&lt;/p&gt;
&lt;p&gt;Disclosure Timeline &lt;br /&gt;
------------------------- &lt;br /&gt;
04 December&amp;nbsp; 2007&amp;nbsp; -- Vendor Contacted&amp;nbsp; &lt;br /&gt;
04 December&amp;nbsp; 2007&amp;nbsp; -- Vendor Replied &lt;br /&gt;
05 December&amp;nbsp; 2007&amp;nbsp; -- Fix Released&amp;nbsp;&lt;br /&gt;
10 December&amp;nbsp; 2007&amp;nbsp; -- Pulic Disclosure &lt;/p&gt;
&lt;p&gt;What is Falt4Extreme &lt;br /&gt;
------------------------ &lt;br /&gt;
Falt4 CMS is a business approved Content Management System (CMS) under the LGPL. The CMS is feature-rich and has a clean administration area. The ultimate CMS with functions for the professional, usable by everyone.CMS modules are available.&lt;/p&gt;
&lt;p&gt;Overview of Vulnerabilities &lt;br /&gt;
------------------------ &lt;br /&gt;
The script is vulnerable to both of XSS and Blind SQL Injection attacks. &lt;/p&gt;
&lt;p&gt;Details of Vulnerabilities &lt;br /&gt;
------------------------ &lt;br /&gt;
1-Blind SQL Injection Vulnerability: &lt;br /&gt;
http://www.EXAMPLE.com/falt4/ &lt;br /&gt;
index.php?handler=cat&amp;amp;nav_ID=1&#039;%20and%20&#039;1&#039;=&#039;1 &lt;br /&gt;
nav_ID parameter is not sanitized properly and can be used for Blind SQL Injection attacks. &lt;br /&gt;
2-Cross Site Scripting Vulnerabilities &lt;br /&gt;
i.http://www.EXAMPLE.com/falt4/ &lt;br /&gt;
index.php?handler=&amp;gt;&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(3)&amp;lt;/script&amp;gt;&amp;amp;nav_ID=1 &lt;br /&gt;
Input passed to the &#039;handler&#039; parameter is not sanitized properly before using and can be used malicious people to perform XSS attacks. &lt;/p&gt;
&lt;p&gt;ii .http://www.EXAMPLE.com/falt4/ &lt;br /&gt;
modules/feed/feed.php?type=rss&amp;amp;lang=1&amp;amp;topic=&amp;gt;&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(2)&amp;lt;/script&amp;gt; &lt;br /&gt;
Input passed to the &#039;topic&#039; parameter is not sanitized properly before using and can be used malicious people to perform XSS attacks. &lt;/p&gt;
&lt;p&gt;Solution &lt;br /&gt;
----------------------- &lt;br /&gt;
Re-download falt4 from sourceforge: &lt;br /&gt;
&lt;a href=&#034;http://downloads.sourceforge.net/falt4/falt4extreme.zip?use_mirror=osdn&#034;&gt;http://downloads.sourceforge.net/falt4/falt4extreme.zip?use_mirror=osdn&lt;/a&gt; &lt;br /&gt;
Replace these files: &lt;br /&gt;
/yourfalt4/index.php &lt;br /&gt;
/yourfalt4/modules/feed.php &lt;br /&gt;
/yourfalt4/admin/index.php &lt;br /&gt;
----------------------- &lt;br /&gt;
The vulnerabilities found on 04 December 2007 &lt;br /&gt;
by Mesut Timur &amp;lt;mesut@h-labs.org&amp;gt; &lt;br /&gt;
H - Security Labs , http://www.h-labs.org &lt;br /&gt;
Gebze Institue of Technology, Computer Engineering, &lt;a href=&#034;http://www.gyte.edu.tr&#034;&gt;http://www.gyte.edu.tr&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
References &lt;br /&gt;
----------------------- &lt;br /&gt;
Vendor Confirmation : &lt;a href=&#034;http://sourceforge.net/forum/forum.php?forum_id=762931&#034;&gt;http://sourceforge.net/forum/forum.php?forum_id=762931&lt;/a&gt;&lt;br /&gt;
Project Site : &lt;a href=&#034;http://sourceforge.net/projects/falt4/&#034;&gt;http://sourceforge.net/projects/falt4/&lt;/a&gt; &lt;br /&gt;
Me : http://www.h-labs.org&lt;/p&gt;</description>
      <category>Advisories</category>
    <comments>http://www.h-labs.org/blog/2007/12/05/falt4_cms_security_report_advisory.html#comments</comments>
    <guid isPermaLink="true">http://www.h-labs.org/blog/2007/12/05/falt4_cms_security_report_advisory.html</guid>
    <pubDate>Wed, 05 Dec 2007 20:24:41 GMT</pubDate>
  </item>
  <item>
    <title>EggBlog v3.1.0 XSS Issues</title>
    <link>http://www.h-labs.org/blog/2007/11/11/eggblog_v3_1_0_xss_issues.html</link>
    <description>
          &lt;div align=&#034;center&#034;&gt;&amp;nbsp;H - Security Labs &lt;br /&gt;
Eggblog v3.1.0 Security Advisory &lt;br /&gt;
ID : HSEC#20071111 &lt;br /&gt;
&lt;/div&gt;
&lt;br /&gt;
General Information&lt;br /&gt;
--------------------------&lt;br /&gt;
Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; : EggBlog v.3.1.0&lt;br /&gt;
Vendor HomePage&amp;nbsp; &amp;nbsp; :http://sourceforge.net/projects/eggblog/ &lt;br /&gt;
Platforms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : PHP &amp;amp;&amp;amp; MySQL&lt;br /&gt;
Vulnerability Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Input Validation Error&lt;br /&gt;
CVE - ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;a href=&#034;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5980&#034;&gt;CVE-2007-5980&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Timeline&lt;br /&gt;
-------------------------&lt;br /&gt;
08 October&amp;nbsp; 2007&amp;nbsp; -- Vendor Contacted&amp;nbsp; &lt;br /&gt;
30 October&amp;nbsp; 2007&amp;nbsp; -- Vendor Replied&lt;br /&gt;
11 November 2007&amp;nbsp; -- New Release&lt;br /&gt;
11 November 2007&amp;nbsp; -- Advisory Released&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What is Eggblog&lt;br /&gt;
------------------------&lt;br /&gt;
eggblog is a free PHP &amp;amp; MySQL blogging package. Features include an internal search engine,photo albums, forums, plug-ins, guest comments to blog articles, automatic monthly archiving of blog articles and RSS XML feeds for both the blog and forums.&lt;br /&gt;
I discovered the security holes when I was testing it for my personel web blog.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Overview&lt;br /&gt;
------------------------&lt;br /&gt;
The script is vulnerable to XSS attacks.&lt;br /&gt;
&lt;br /&gt;
Details About Vulnerability&lt;br /&gt;
------------------------&lt;br /&gt;
XSS Vulnerability(home/rss.php)&lt;br /&gt;
&lt;br /&gt;
At the rss.php line 6-7; there are unfiltered PHP_SELFs that can be used for XSS attacks.&lt;br /&gt;
---------&lt;br /&gt;
&amp;lt;a&lt;br /&gt;
href=\&amp;quot;../rss/blog.php\&amp;quot;&amp;gt;&amp;quot;.$_SERVER[&#039;SERVER_NAME&#039;].str_replace (&amp;quot;/home/rss.php&amp;quot;,&amp;quot;&amp;quot;,$_SERVER[&#039;PHP_SELF&#039;]).&amp;quot;/rss/blog.php&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;a&lt;br /&gt;
href=\&amp;quot;../rss/topics.php\&amp;quot;&amp;gt;&amp;quot;.$_SERVER[&#039;SERVER_NAME&#039;].str_replace (&amp;quot;/home/rss.php&amp;quot;,&amp;quot;&amp;quot;,$_SERVER[&#039;PHP_SELF&#039;]).&amp;quot;/rss/topics.php&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&lt;br /&gt;
---------&lt;br /&gt;
&lt;br /&gt;
The attacker can succesfully launch XSS attacks with loading payload on to the URL after the home\rss.php. For example :&lt;br /&gt;
http://www.example.com/home/rss.php/&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
Solutions&lt;br /&gt;
-----------------------&lt;br /&gt;
Download the new release : EggBlog v3.1.1&lt;br /&gt;
&lt;br /&gt;
Credits&lt;br /&gt;
-----------------------&lt;br /&gt;
The vulnerabilities found on 08 October 2007&lt;br /&gt;
by Mesut Timur &amp;lt;mesut@h-labs.org&amp;gt;&lt;br /&gt;
H - Security Labs , http://www.h-labs.org&lt;br /&gt;
Gebze Institue of Technology, Computer Engineering, http://www.gyte.edu.tr&lt;br /&gt;
&lt;br /&gt;
References&lt;br /&gt;
-----------------------&lt;br /&gt;
http://sourceforge.net/forum/forum.php?forum_id=753622&lt;br /&gt;
http://www.eggblog.net&lt;br /&gt;
http://sourceforge.net/projects/eggblog/&lt;br /&gt;
http://www.h-labs.org</description>
      <category>Advisories</category>
    <comments>http://www.h-labs.org/blog/2007/11/11/eggblog_v3_1_0_xss_issues.html#comments</comments>
    <guid isPermaLink="true">http://www.h-labs.org/blog/2007/11/11/eggblog_v3_1_0_xss_issues.html</guid>
    <pubDate>Sun, 11 Nov 2007 20:13:16 GMT</pubDate>
  </item>
  </channel>
</rss>
