PerlDiver
   >> Bug Reports
Thread views: 11793

Print Thread
bugz
(stranger )
09/15/05 07:49 PM
XSS Vulnerability  

The following discusses a potential security vulnerability affecting one of your products. We are bringing it to your attention in order to assist you in investigating it and determining the appropriate actions, and have provided preliminary information about the potential vulnerability below. Please read our disclosure policy, available at http://www.exploitlabs.com/disclosure-policy.html if you have any questions. Please note the section under "Phases" Please confirm using the contact information I have provided below that
you have received this note.

We look forward to working with you,

Exploitlabs Research Team
Donnie werner http://exploitlabs.com

- EXPL-A-2005-014 exploitlabs.com Advisory 043 -perldiver -

AFFECTED PRODUCTS
=================
Perldiver v1.x and 2.x
http://scriptsolutions.com/

OVERVIEW
========
Perl Diver digs into your server's perl installation and giving you the information you need and quick and easy to find manner.

DETAILS
=======
1. XSS

Perldiver does not properly filter malicious script content. XSS my be inserted in the "module" parameter. ( v2.x ) or as a GET request in the main script ( v1.x )

The malicious script is the rendered and is executed in the context of the users brower.

POC
===

1.x
------
http://[host]/[path]/perldiver.pl?testhere<SCRIPT>alert(document.domain);</SCRIPT>


2.x
------
http://[host]/[path]/perldiver.cgi?action=2020&module=<script>document.write(document.domain)</script>

bonus vendor site vuln:
http://www.scriptsolutions.com/programs/free/perldiver/perldiver.cgi?action=2020&module=<script>document.write(document.domain)</script>

SOLUTION:
=========
vendor contact:
http://www.scriptsolutions.com/support/postlist.pl?Cat=&Board=DDBugs
no response Sept 14, 2005

Credits
=======
This vulnerability was discovered and researched by Donnie werner of exploitlabs

mail: wood at exploitlabs.com
mail: morning_wood at zone-h.org
--
web: http://exploitlabs.com
web: http://zone-h.org

Edited by Programmer (11/06/05 12:24 PM)

Post Extras Print Post


 
Entire thread
Subject  Posted byPosted on
.XSS Vulnerability  bugz09/15/05 07:49 PM
.*XSS Vulnerability  ProgrammerAdministrator09/16/05 12:29 PM
Jump to

 

Domain Name Registration
Register your .com, .net, .org, .biz, .info, and/or .us domain name with NICForce and save more than 50% over the monopoly prices charged by other domain registrars.

¯¯¯¯¯¯¯¯¯
click here!

Managed DNS & Domain Forwarding
Take control of your domain name today! Five minute propagation of changes; Full zone management functionality: Domain forwarding options.

¯¯¯¯¯¯¯¯¯
click here!

E-Mail Hosting
Get your personalized me@mydomain.com e-mail address from $15.95/year. Professional, personalized e-mail services with your own unique domain name without the added cost of web site hosting.

¯¯¯¯¯¯¯¯¯
click here!

Ventrilo VoIP Servers
Save on long distance charges with our live-voice-chat Ventrilo servers! Great for multi-player gaming. Choose from 11 server locations in the U.S., Canada, and Europe.

¯¯¯¯¯¯¯¯¯
click here!

Domain & Web Hosting
True premium web, domain, and e-mail hosting! Generous disk space and bandwidth allocations; Reliable Linux hosting; Web-based control panel; MySQL; PHP; ASP; and much, much more!

¯¯¯¯¯¯¯¯¯
click here!

© 1997-2007, TNS Group, Inc.