se_cur_ity at hotmail.com
Fri Jun 9 20:56:01 BST 2006
- EXPL-A-2006-003 exploitlabs.com Retro Advisory 001 -
- ASPListpics -
Nov 11, 2004
Duplicate Release: June 06, 2006
ASPListpics is a highly configurable ASP application that automatically
generates fast thumbnail web indexes of images in a folder structure.
1. XSS ( persistant )
PROOF OF CONCEPT LINKS AND RETRO-POC
1. XSS ( Cross Site Scripting )
There is persistant XSS inclusion in the "comments"
feature of ASPListpics in the following:
By embedding various types of XSS into the comment
below is a simple PoC ( Proof of Concept )
enter into the "comments" section malicious script.
comment: ohno<iframe src="http://whatismyip.com"></iframe>ouch
and is rendered as:
SCRIPTING HERE >9000|0
r0t - http://pridels.blogspot.com/2006/06/asp-listpics-43-xss-vuln.html
This vulnerability was discovered and researched by
Donnie Werner of exploitlabs. At the original time
of discovery and retro-release date, the author was
not aware of any other advisories or patches available.
Retro-Advisories are released when either the same research
is released by a 3rd party, old private research that is no longer
active, or the product has been patched due to Vendor updates
before a formal Exploitlabs advisory was released to the public.
wood at exploitlabs.com
morning_wood at zone-h.org
Full-Disclosure is hosted and sponsored by Secunia.