exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

outblazeXSS.txt

outblazeXSS.txt
Posted Feb 6, 2006
Site morx.org

The Outblaze Email system suffers from XSS.

tags | advisory
SHA-256 | 66ecb829477fcb7e729ee1311825593466307afe12e8425b74c11da9e5ef239f

outblazeXSS.txt

Change Mirror Download
Title: outblaze Cross Site Scripting

Author: Simo Ben youssef aka _6mO_HaCk <simo_at_morx_org>
Discovered: 23 january 2005
Published: 02 february 2006
MorX Security Research Team
https://www.morx.org
Original advisory: https://www.morx.org/outblazeXSS.txt

Service: Webmail manager

Vendor: outblaze / www.outblaze.com

Vulnerability: Cross Site Scripting / Cookie-Theft / Relogin attacks

Severity: Medium/High

Details:

With over 40 million mailboxes under Outblaze management, Outblaze
provided enhanced messaging services to telcos, service providers, VARs,
Carriers and Corporations on an outsoucing basis, The core product is an
advanced email system with several available ancillary services.
throw.main outblaze script is prone to cross-site scripting attacks.
This problem is due to a failure in the application to properly sanitize
user-supplied input. input can be passed in variable $file

Impact:

an attacker can exploit the vulnerable scripts to have arbitrary script
code executed in the browser of an authentified outblaze user in the
context of the vulnerable website. resulting in the theft of cookie-based
authentication giving the attacker full access to the victim's email
account as well as other type of attacks.


Examples:

https://www.vulnerable-site.com/scripts/common/throw.main?file=<BODY%20ONLOAD=alert('vul')>



screen capture:

https://www.morx.org/mailXSS.jpg

Disclaimer:

this entire document is for eductional, testing and demonstrating purpose
only. Modification use and/or publishing this information is entirely on
your OWN risk. The information provided in this advisory is to be
used/tested on your OWN machine/Account. I cannot be held responsible for
any of the above.



Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close