------------------------------------------------------------ - EXPL-A-2005-010 exploitlabs.com Advisory 039 - ------------------------------------------------------------ - Mac OSX Server weblog - AFFECTED PRODUCTS ================= Mac OSX 10.4.0 Weblog Server http://apple.com OVERVIEW ======== Weblog Server, which simplifies the publication of Weblogs. It provides users with the ability to publish and syndicate their Web content using existing Web browsers, including Apple's own Safari software. Features include calendar-based navigation, user and group blogs and HTML, RSS, RSS2, RDF and ATOM protocols, as well as "Apple-designed blog themes." Weblog Server can also integrate with Open Directory, LDAP and access control lists for authentication. DETAILS ======= 1. XSS Mac Server weblog comments does not properly filter malicious script content. XSS my be inserted in the author and comment body sections. The malicious script is the rendered upon visitation and executed in the context of the users brower. http://[host]:16080/weblog/[bloguser]/?permalink=[blogentry]&page=comments POC === 1. ------ input malicious script into author and comment sections in the comment option on the weblog. eg: [cookie theft] eg: [redirect] http://[host]:16080/weblog/[bloguser]/?permalink=[blogentry]&comment=y&page=comments&category=%2F&author=[script]&authorEmail=&authorURL=&commentText=[script]&submit=Submit+Comment SOLUTION: ========= vendor contact: product-security@apple.com June 11, 2005 patch released: Weblog Server CVE-ID: CAN-2005-2523 Available for: Mac OS X Server v10.4.2 patch available: http://www.apple.com/support/downloads/securityupdate2005007macosx1042server.html Credits ======= This vulnerability was discovered and researched by Donnie Werner of exploitlabs Donnie Werner mail: wood at exploitlabs.com mail: morning_wood at zone-h.org -- web: http://exploitlabs.com web: http://zone-h.org original: http://exploitlabs.com/files/advisories/EXPL-A-2005-010-mac-weblog.txt _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/