Bugtraq mailing list archives

Vulnerabilities in IB Promotion Advanced Business Web Suite


From: "MustLive" <mustlive () websecurity com ua>
Date: Mon, 20 Sep 2010 18:53:52 +0300

Hello Bugtraq!

I want to warn you about Cross-Site Scripting and Insufficient
Anti-automation vulnerabilities in IB Promotion Advanced Business Web Suite.
It's Ukrainian commercial CMS.

XSS (WASC-08):

http://site/search/?qs=’;alert(document.cookie);//

It's DOM Based XSS.

Insufficient Anti-automation (WASC-21):

http://site/register/
http://site/lostpasswd/

At these pages there is no protection from automated requests.

Affected products:

IB Promotion Advanced Business Web Suite v1.0, IB Pro CMS v1.0 and IB Pro
CMS v2.0. IB Promotion Advanced Business Web Suite - it's previous name of
system IB Pro CMS.

Timeline:

2010.06.22 - informed admin of the site, where I found vulnerabilities.
2010.06.23 - announced at my site.
2010.06.24 - informed developers of CMS.
2010.09.09 - disclosed at my site. Both admin of vulnerable site and
developers (in their engine and at their own site) didn't fix the holes.

I mentioned about these vulnerabilities at my site
(http://websecurity.com.ua/4313/).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua



Current thread: