| To: | bugtraq@securityfocus.com |
|---|---|
| Subject: | Movable Type <= 3.33 XSS Exploit |
| From: | teracci2002@yahoo.co.jp |
| Date: | Fri, 26 Jan 2007 17:52:54 +0900 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
[Description] MT (Movable Type) is a Blog software. MT has a XSS filter to remove scripts from user inputs, but there are ways to evade the filter using malformed input. [Affected] Movable Type <= 3.33 [Exploit] By the default, Blog readers are allowed to post comments containing html tags. Attackers may post malformed comments as below. 1. NULL byte in number entitiy reference. <A href="javascript[0x00]8;alert();">link</A> 2. Unfinished tag in the tail of comment. <P><BR style="xss:expression(alert())" MT's filter fails to sanitize these comments. Scripts in these comments may run in certain browsers (maybe in IE ONLY). [Impact] - Cookies theft. - Web pages defacing. [Solution] Upgrade MT to the newest version. Six Apart fixed these problems in v3.34. [Links] http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html See #46226. ---- teracci2002@yahoo.co.jp |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed, Matteo Beccati |
|---|---|
| Next by Date: | Re: Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting, sirdarckcat |
| Previous by Thread: | [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed, Matteo Beccati |
| Next by Thread: | [ GLSA 200701-24 ] VLC media player: Format string vulnerability, Matthias Geerdsen |
| Indexes: | [Date] [Thread] [Top] [All Lists] |