Grégory Le Bras
27/03/03, 19:20
__________________________________________________ ______________________
Security Corporation Security Advisory [SCSA-013]
__________________________________________________ ______________________
PROGRAM: Ceilidh
HOMEPAGE: http://www.lilikoi.com
VULNERABLE VERSIONS: 2.70 and prior
__________________________________________________ ______________________
DESCRIPTION
__________________________________________________ ______________________
"Ceilidh is a Web-based threaded discussion engine that features
automatic text to HTML conversion, file attachment, e-mail
notification, automatic message expiration, multiple levels of
security and much more."
(direct quote from http://www.lilikoi.com)
DETAILS & EXPLOITS
__________________________________________________ ______________________
¤ Cross Site Scripting :
A exploitable bug was found on Ceilidh which cause script
execution on client's computer by following a crafted url.
This kind of attack known as "Cross-Site Scripting Vulnerability" is
present in testcgi.exe file, an attacker can input specially crafted
links and/or other malicious scripts.
- Exploits :
http://[target]/cgi-bin/testcgi.exe?[hostile_code]
The hostile code could be :
alert("Cookie="+document.cookie)
(open a window with the cookie of the visitor.)
(replace [] by <>)
SOLUTIONS
__________________________________________________ ______________________
No solution for the moment.
VENDOR STATUS
__________________________________________________ ______________________
The vendor has reportedly been notified.
LINKS
__________________________________________________ ______________________
- http://www.security-corp.org/index.php?ink=4-15-1
- Version Française :
http://www.security-corporation.com/index.php?id=advisories&a=013-FR
------------------------------------------------------------------------
Grégory Le Bras aka GaLiaRePt | http://www.Security-Corporation.com
------------------------------------------------------------------------
Security Corporation Security Advisory [SCSA-013]
__________________________________________________ ______________________
PROGRAM: Ceilidh
HOMEPAGE: http://www.lilikoi.com
VULNERABLE VERSIONS: 2.70 and prior
__________________________________________________ ______________________
DESCRIPTION
__________________________________________________ ______________________
"Ceilidh is a Web-based threaded discussion engine that features
automatic text to HTML conversion, file attachment, e-mail
notification, automatic message expiration, multiple levels of
security and much more."
(direct quote from http://www.lilikoi.com)
DETAILS & EXPLOITS
__________________________________________________ ______________________
¤ Cross Site Scripting :
A exploitable bug was found on Ceilidh which cause script
execution on client's computer by following a crafted url.
This kind of attack known as "Cross-Site Scripting Vulnerability" is
present in testcgi.exe file, an attacker can input specially crafted
links and/or other malicious scripts.
- Exploits :
http://[target]/cgi-bin/testcgi.exe?[hostile_code]
The hostile code could be :
alert("Cookie="+document.cookie)
(open a window with the cookie of the visitor.)
(replace [] by <>)
SOLUTIONS
__________________________________________________ ______________________
No solution for the moment.
VENDOR STATUS
__________________________________________________ ______________________
The vendor has reportedly been notified.
LINKS
__________________________________________________ ______________________
- http://www.security-corp.org/index.php?ink=4-15-1
- Version Française :
http://www.security-corporation.com/index.php?id=advisories&a=013-FR
------------------------------------------------------------------------
Grégory Le Bras aka GaLiaRePt | http://www.Security-Corporation.com
------------------------------------------------------------------------