Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VULNERABILITIES - January 4, 2006

Jan 3, 2006 11:41PM PST

TITLE:
vBulletin "Add Reminder" Script Insertion Vulnerability

SECUNIA ADVISORY ID:
SA18299

VERIFY ADVISORY:
http://secunia.com/advisories/18299/

CRITICAL:
Moderately critical

IMPACT:
Cross Site Scripting

WHERE:
From remote

SOFTWARE:
vBulletin 3.x
http://secunia.com/product/3212/

DESCRIPTION:
trueend5 has reported a vulnerability in vBulletin, which can be
exploited by malicious people to conduct script insertion attacks.

Input passed to the "title" field in "calendar.php" when adding a
"Single, All Day", "Ranged", or "Recurring" event isn't properly
sanitised before being used. This can be exploited to inject
arbitrary HTML and script code, which will be executed in a user's
browser session in context of an affected site when the malicious
user data is viewed via the "Add Reminder" functionality (i.e. when
visiting "calendar.php?do=addreminder&e=[eventid]").

The vulnerability has been reported in version 3.5.2. Other versions
may also be affected.

SOLUTION:
Edit the source code to ensure that input is properly sanitised.

PROVIDED AND/OR DISCOVERED BY:
trueend5, Security Science Researchers Institute Of Iran

ORIGINAL ADVISORY:
http://kapda.ir/advisory-177.html

Discussion is locked