Vulnerabilities in IB Promotion Advanced Business Web Suite

From: MustLive <mustlive@websecurity.com.ua>
To: bugtraq@securityfocus.com
Cc:
Subject: Vulnerabilities in IB Promotion Advanced Business Web Suite
Date:


Hello Bugtraq!

I want to warn you about Cross-Site Scripting and Insufficient
Anti-automation vulnerabilities in IB Promotion Advanced Business Web Suite.
It's Ukrainian commercial CMS.

XSS (WASC-08):

http://site/search/?qs=\u2019;alert(document.cookie);//

It's DOM Based XSS.

Insufficient Anti-automation (WASC-21):

http://site/register/
http://site/lostpasswd/

At these pages there is no protection from automated requests.

Affected products:

IB Promotion Advanced Business Web Suite v1.0, IB Pro CMS v1.0 and IB Pro
CMS v2.0. IB Promotion Advanced Business Web Suite - it's previous name of
system IB Pro CMS.

Timeline:

2010.06.22 - informed admin of the site, where I found vulnerabilities.
2010.06.23 - announced at my site.
2010.06.24 - informed developers of CMS.
2010.09.09 - disclosed at my site. Both admin of vulnerable site and
developers (in their engine and at their own site) didn't fix the holes.

I mentioned about these vulnerabilities at my site
(http://websecurity.com.ua/4313/).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua






Copyright © 1995-2019 LinuxRocket.net. All rights reserved.