[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAESCr8PDfK4jsmCxs4TsxoCWxn5cqJ1Cv4_s_+kSYOay4Ad2hQ@mail.gmail.com>
Date: Thu, 22 Sep 2011 23:41:36 +0300
From: Netsparker Advisories <advisories@...itunasecurity.com>
To: bugtraq@...urityfocus.com, full-disclosure@...ts.grok.org.uk
Subject: XSS Vulnerabilities in TWiki < 5.1.0
Information------------------Name : XSS vulnerability in TWikiSoftware
: TWiki 5.0.2 and below.Vendor Hompeage :
http://twiki.org/Vulnerability Type : Cross-Site ScriptingSeverity :
HighResearcher : Mesut Timur <mesut [at] mavitunasecurity [dot]
com>Advisory Reference : NS-11-006CVE : CVE-2011-3010
Description-----------------------------------TWiki® is a flexible,
powerful, and easy to use enterprise wiki,enterprise collaboration
platform, and web application platform. It isa Structured Wiki,
typically used to run a project development space,a document
management system, a knowledge base, or any other groupwaretool, on an
intranet, extranet or the Internet.
Details-----------------------------------TTWiki is affected by XSS
vulnerabilities in version 5.0.2.Example PoC url is as follows :
http://example.com/do/view/Main/Jump?create=on&newtopic=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert%280x0051D1%29%3C/script%3E&template=WebCreateNewTopic&topicparent=3http://example.com/do/view/TWiki/ATasteOfTWiki?'"--></style></script><script>alert(0x002B48)</script>
You can read the full article about Cross-Site
Scriptingvulnerabilities from here
:http://www.mavitunasecurity.com/crosssite-scripting-xss/
Solution-----------------------------------Upgrade to the latest TWiki
version (5.1.0).
Credits-----------------------------------It has been discovered on
testing of Netsparker, Web ApplicationSecurity Scanner -
http://www.mavitunasecurity.com/netsparker/.
References-----------------------------------Vendor Url :
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2011-3010MSL
Advisory Link :
http://www.mavitunasecurity.com/xss-vulnerability-in-twiki5/Netsparker
Advisories : http://www.mavitunasecurity.com/netsparker-advisories/
About Netsparker-----------------------------------Netsparker® can
find and report security issues such as SQL Injectionand Cross-site
Scripting (XSS) in all web applications regardless ofthe platform and
the technology they are built on. Netsparker's uniquedetection and
exploitation technique
--
Netsparker Advisories, <advisories@...itunasecurity.com>
Homepage, http://www.mavitunasecurity.com/netsparker-advisories/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists