by r0t,der4444,cembo,VietMafia

Tuesday, December 06, 2005

XcClassified v3.x XSS vuln

XcClassified v3.x XSS vuln

Vuln. dicovered by : r0t
Date: 6 dec. 2005
vendor:http://www.xcclassified.com/
affected version: v3.x and prior



Product Description:
Get XcClassified, the leading ASP classified ads software! Add the power of internet ad listings to any web site.
Since XcClassified is highly customizable, you have the power to make changes in both its look and functionality. Its look and feel can be quickly and easily adjusted to seem 100% integrated with the rest of your web site's design. You can even customize the text and currency for any language or locale. A variety of configuration options make it easy to tailor XcClassified to suit your preferences.


Vuln. Description:
XcClassified contains a flaw that allows a remote cross site scripting attack. This flaw exists because input passed to the search paremters in "CPSearch.asp" isn't properly sanitised before being returned to the user.
This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.


Solution:
Edit the source code to ensure that input is properly sanitised.

0 Comments:

Post a Comment

<< Home

 
Copyright (c) 2006 Pridels Sec Crew