Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

MagpieRSS XSS 0day
From: admin () elites0ft com
Date: 28 Dec 2008 22:50:56 -0000

Hello,

I have found a Cross Site Scripting vulnerability in MagpieRSS, an RSS parser written in PHP, basically, this piece of 
software enables users to add their own RSS feeds to be parsed, so they can keep up to date with their favourite feeds, 
as well as the pre-defined ones.

I crafted my own RSS feed, which contains XSS inside the CDATA.

Here is the XML file I used: http://www.elites0ft.com/poc.xml

If for example, I ask a user to subscribe to my feed, after disguising it as a real feed, I then go and update it with 
malicious content, the RSS parser will then parse the updated content and the user will end up loading an Iframe with a 
cookie stealer inside.

The reason this happens is because the CDATA is not getting escaped, it is a simple fix: htmlentities() around the 
parsed CDATA.

This is a potentially harmful exploit if you can convince users to add your feed.

Thanks for reading,
system_meltdown.
[Elites0ft.com]


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]