| To: | vulnwatch@vulnwatch.org |
|---|---|
| Subject: | [VulnWatch] XSS vulnerability in OFBIZ forum |
| From: | Ēriks <eriks00@moon.lv> |
| Date: | Fri, 8 Dec 2006 17:35:36 +0200 (EET) |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | vulnwatch-list@securepoint.com |
| Delivered-to: | mailing list vulnwatch@vulnwatch.org |
| Delivered-to: | moderator for vulnwatch@vulnwatch.org |
| Importance: | Normal |
| List-help: | <mailto:vulnwatch-help@vulnwatch.org> |
| List-post: | <mailto:vulnwatch@vulnwatch.org> |
| List-subscribe: | <mailto:vulnwatch-subscribe@vulnwatch.org> |
| List-unsubscribe: | <mailto:vulnwatch-unsubscribe@vulnwatch.org> |
| Mailing-list: | contact vulnwatch-help@vulnwatch.org; run by ezmlm |
| User-agent: | SquirrelMail/1.4.8 |
Open source ERP and e-commerce package OFBIZ has an XSS vulnerability in the forum functionality. This was initially posted on Ofbiz JIRA issue tracking system (https://issues.apache.org/jira/browse/OFBIZ-178) on 22/Aug/06. I last verified it in revision 469895 (1/Nov/06), and it was still present. As far as I know (and from activity on JIRA) nothing has changed. Repeating the vulnerability is straight forward: 1) Install OFBIZ; 2) Disable JavaScript in browser; 3) Log in and browse to forum (with default install you will see Browse Forums/Gizmos on the left side); 4) Post a message like <script>alert('XSS vulnerability test');</script> 5) Enable JavaScript; So if you are a customer going to some vendor's OFBIZ site, don't go to Forums section as you might be affected (if your JavaScript is enabled). If you are using OFBIZ for your e-commerce site, disable all forum functionality until the vulnerability is fixed. Ēriks Dobelis http://www.biti.lv/ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [VulnWatch] Orkut Multiple Cross Site Scripting Vulnerabilities, Rajesh Sethumadhavan |
|---|---|
| Next by Date: | [VulnWatch] iDefense Security Advisory 12.12.06: Sun Microsystems Solaris ld.so 'doprf()' Buffer Overflow Vulnerability, iDefense Labs |
| Previous by Thread: | [VulnWatch] Orkut Multiple Cross Site Scripting Vulnerabilities, Rajesh Sethumadhavan |
| Next by Thread: | [VulnWatch] iDefense Security Advisory 12.12.06: Sun Microsystems Solaris ld.so 'doprf()' Buffer Overflow Vulnerability, iDefense Labs |
| Indexes: | [Date] [Thread] [Top] [All Lists] |