exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

jawsGlossary.txt

jawsGlossary.txt
Posted Aug 14, 2005
Authored by Paulino Calderon | Site nah.suckea.com

Jaws Glossary version 0.4 through 0.5.1 suffer from cross site scripting flaws.

tags | exploit, xss
SHA-256 | e991bfb30f2a1a7245f48d2e163c87e0ac4bb872253d33e7407bbdf4b33c4c0b

jawsGlossary.txt

Change Mirror Download
XSS Bug in Jaws Glossary( v 0.4 - 0.5.1 (latest version))

STATUS: The vendor has been contacted, fixed in cvs.

Jaws is a Framework and Content Management System for building dynamic
web sites. It aims to be User Friendly
giving ease of use and lots of ways to customize web sites, but at the
same time is Developer Friendly,
it offers a simple and powerful framework to hack your own modules.

TECHNICAL INFO
================================================================

The Glossary gadget doesn't filter dangerous characters in the argument
view or ViewTerm ( according to the version)
allowing the instertion of items from
"<script>alert(document.cookie)</script> to more complex situations.

Example:

v0.5.x:
https://url.com/index.php?gadget=Glossary&action=ViewTerm&term=<script
src=some script</script>
v 0.4:
https://url.com/index.php?gadget=Glossary&action=view&term=<script
src=some script></script>


An attacker may leverage this issue to have arbitrary script code
executed in the browser of an unsuspecting user.
This may facilitate the theft of cookie-based authentication credentials
as well as other attacks.

VULNERABLE VERSIONS
---------------------------------------------------------------
0.4-0.5.1(Latest version)


---------------------------------------------------------------
Contact information
:Paulino Calderon
:nah@suckea.com
:https://nah.suckea.com/
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close