[KAPDA::#12] - ekinboard XSS and HTML Injection KAPDA New advisory Vendor: http://www.ekinboard.com Vulnerable Version: 1.0.3 Bug: XSS and HTML Injection Exploitation: Remote with browser Description: -------------------- ekinboard is an open source forum software designed and programmed by ekindesigns. It is constantly being updated and is always getting easier to use! Vulnerability: -------------------- HTML Injection: The software does not properly filter HTML tags in post titles that may allow a remote user to inject HTML/javascript codes. The hostile code may be rendered in the web browser of the victim user who will visit the board (persistent). XSS: XSS Vulnerability in 'profile.php' "user rating" that may allow a remote user to launch cross-site scripting attacks. This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected Web site.(victim must be logged in to enable rating) Demonstration URL : -------------------- http://localhost/ekinboard/profile.php?id=2'%3E%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E Solution: -------------------- There is no vendor-supplied patch for this issue at this time. More Detail: -------------------- http://irannetjob.com/content/view/162/28/ Credit : -------------------- Discovered & released by trueend5 (trueend5 kapda ir) Security Science Researchers Institute Of Iran [http://www.KAPDA.ir] __________________________________ Yahoo! FareChase: Search multiple travel sites in one click. http://farechase.yahoo.com