#######################################################################<br><br> Fredrick Diggle Security Advisory<br><br>Application: The Internet<br>Versions: All Versions Affected<br>Platforms: All Platforms Affected
<br>Bugs: XSS (Xtra Serious Software bugs)<br>Exploitation: Remote<br>Severity: Xtreme!!!!<br>Date: 15 Dec 2007<br>Credit: Fredrick Diggle<br><br>#######################################################################<br>
<br>1) Introduction<br>2) Bugs<br>4) Fix<br><br>#######################################################################<br><br>===============<br>1) Introduction<br>===============<br><br>Fredrick Diggle Security Services is probably the best application security researchers on the scene this week. They have identified several hundred thousand vulnerabilities this week for which Priv8 0dayz have been developed. Fredrick Diggle Security Team has decided to release several of these vulnerabilities to the community at large (Pre Vendor Release!!!!). Fred Diggle would like to ensure that you understand this is 0DAY!!!. The vendors are completely unaware of this vulnerabilities.
<br><br>#######################################################################<br><br>=======<br>2) Bugs<br>=======<br><br>Dragonfly <a href="http://9.6.0.1">9.6.0.1</a><br> <br> echo isset($_GET['cat']) ? '&cat=' . $_GET['cat'] : '&cat=0' <--- XSS OMG!
<br> <br>Gael 0.4<br> <br> echo $_GET["idel"]; <--- More XSS :/<br> <br>Horde 3.1.3<br><br> echo isset($_GET['ext']) ? $_GET['ext'] : '' <--- This is an XSS vulnerability<br> <br>
SQLiteManager 1.2.0<br><br> echo $_GET["lang"] <--- Hold me... I fear<br> <br>ampache <a href="http://3.3.2.1">3.3.2.1</a><br><br> echo "<img src=\"" . conf('web_path') . "/albumart.php?id=" . $_GET['id'] . "\" border=\"0\" />"; <--- The end is near :<
<br> <br>Amp 3.6.0<br><br> echo '<tr><td colspan="6"><b class="red">'. $_GET['msg'] .'</b></td></tr>'; <--- Danger Will Robinson<br> <br>
Twig 2.8.3<br><br> echo "<input type=\"hidden\" name=\"cc\" value=\"" . $_GET["cc"] . "\">\n"; <--- Fredrick Diggle is out of ideas<br> <br>Fredrick Diggle would like you to note that this is very small subset of the 0dayz that Fredrick Diggle Security Team has available. If you are rich and would like to buy our Exploit codez Fredrick Diggle would very much like to hear from you.
<br><br><br>#######################################################################<br><br>======<br>4) Fix<br>======<br><br>There is no fix :> We are doomed :<<br><br>#######################################################################
<br>