lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <BAY19-DAV2F1A44B0D71E8E03F375CD9B10@phx.gbl>
Date: Tue Aug 16 00:16:58 2005
From: se_cur_ity at hotmail.com (Morning Wood)
Subject: Apple Mac Tiger 10.4 weblog server

------------------------------------------------------------
      - EXPL-A-2005-010 exploitlabs.com Advisory 039 -
------------------------------------------------------------
                       - Mac OSX Server weblog -





AFFECTED PRODUCTS
=================
Mac OSX 10.4.0 Weblog Server

http://apple.com



OVERVIEW
========
Weblog Server, which simplifies the publication of Weblogs.
 It provides users with the ability to publish and syndicate
 their Web content using existing Web browsers, including
 Apple's own Safari software. Features include calendar-based
 navigation, user and group blogs and HTML, RSS, RSS2, RDF
 and ATOM protocols, as well as "Apple-designed blog themes."
 Weblog Server can also integrate with Open Directory, LDAP
 and access control lists for authentication.




DETAILS
=======
1. XSS

Mac Server weblog comments does not properly filter
malicious script content. XSS my be inserted in the
author and comment body sections. The malicious script
is the rendered upon visitation and executed in the
context of the users brower.

http://[host]:16080/weblog/[bloguser]/?permalink=[blogentry]&page=comments



POC
===

1.
------
input malicious script into author and comment sections in
the comment option on the weblog.
eg:<SCRIPT>alert(document.cookie);</SCRIPT> [cookie theft]
eg:<iframe src="http://somesite.com"></iframe> [redirect]


http://[host]:16080/weblog/[bloguser]/?permalink=[blogentry]&comment=y&page=comments&category=%2F&author=[script]&authorEmail=&authorURL=&commentText=[script]&submit=Submit+Comment


SOLUTION:
=========
vendor contact:
product-security@...le.com June 11, 2005

patch released:

Weblog Server
CVE-ID: CAN-2005-2523
Available for: Mac OS X Server v10.4.2

patch available:
http://www.apple.com/support/downloads/securityupdate2005007macosx1042server.html





Credits
=======
This vulnerability was discovered and researched by
Donnie Werner of exploitlabs

Donnie Werner

mail:   wood at exploitlabs.com
mail:   morning_wood at zone-h.org
-- 
web: http://exploitlabs.com
web: http://zone-h.org

original:
http://exploitlabs.com/files/advisories/EXPL-A-2005-010-mac-weblog.txt

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ