Thursday, 17 September 2009 00:00
The Joomla component EasyBook 2.0.0rc4 suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit.
BBCode XSS
Settings:
- Allow BBCode - on (default)
- Allow Pictures - on (not default)
[img]fake.png" onerror="alert(String.fromCharCode(88,83,83))[/img]
Website URL XSS
Settings:
- Show web site field: Show (default)
foo.com" onmouseover="alert(String.fromCharCode(88,83,83));return false;
Requires minimal user interaction
Skype/Yahoo Username XSS
Very narrow scope, as entries are truncated. XSS still technically possible. Requires user interaction.
' onclick="alert('XSS')"
AIM/MSN Username XSS
Again, narrow scope. See 3.
" onclick="alert('xss')"
ICQ username is similar, but scope seems too narrow to exploit.
Timeline
- Vulnerabilites Discovered: 10 July 2009
- Vendor Notified: 10 July 2009
- Vender Response: 13 July 2009
- Update Available: ... 2009
- Disclosure: 17 September 2009
Last Updated on Thursday, 17 September 2009 22:31
Comments (1)
Add your comment
Featured Extensions
|
$1.00
FREE You Save: $1.00 |
$3.00
|
$3.00
|
FREE
|




This version includes security updates and bug fixes!
Download and information: http://www.kubik-rubik.de/joomla-hilfe/komponente-easybook-2-reloaded-joomla