Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Cross-Site Scripting vulnerability in 3D Cloud for Joomla
From: "MustLive" <mustlive () websecurity com ua>
Date: Tue, 26 Jan 2010 20:53:04 +0200

Hello Full-Disclosure!

I want to warn you about Cross-Site Scripting vulnerability in 3D Cloud
(mod_3dcloud) plugin for Joomla. Which I found and disclosed at 22.01.2010.

It is similar to XSS vulnerability in JVClouds3D for Joomla
(http://websecurity.com.ua/3839/). About millions of flash files
tagcloud.swf which are vulnerable to XSS attacks I mentioned in my article
XSS vulnerabilities in 34 millions flash files



Code will execute after click. It's strictly social XSS.

Also it's possible to conduct HTML Injection attack, including in those
flash files which have protection (in flash files or via WAF) against
javascript and vbscript URI in parameter tagcloud.

HTML Injection:


Vulnerable are 3D Cloud 1.3 and previous versions.

I mentioned about this vulnerability at my site

Best wishes & regards,
Administrator of Websecurity web site

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • Cross-Site Scripting vulnerability in 3D Cloud for Joomla MustLive (Jan 27)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]