Home page logo

fulldisclosure logo Full Disclosure mailing list archives

XSS in Squirrelmail plugin 'Virtual Keyboard' <= 0.9.1
From: Moritz Naumann <security () moritz-naumann com>
Date: Tue, 05 Oct 2010 18:28:28 +0200


Squirrelmail plugin 'Virtual Keyboard' version 0.9.1 and lower is
vulnerable to cross site scripting (XSS).

The vkeyboard.php script fails to sanitize the value of HTTP GET
parameter 'passformname' which the script stores in a variable of the
same name and outputs (unmodified) into a HTML document later. As such,
it is possible to inject client-evaluated HTML and script code into the
output generated by the application.

For proof of concept, accessing the following location ([Base_URL]
refers to a Squirrelmail installation with a vulnerable version of the
'Virtual Keyboard' plugin) results in a javascript generated alert
windows reading 'XSS' popping up:

'Virtual Keyboard' installations can be found using this 'Google dork':

This vulnerability was originally reported in early May 2010.
A suitable update fixing this issue, Virtual Keyboard v0.9.2 for
Squrrelmail 1.4.x, has been provided to the Squirrelmail developers and
me by Daniel Kobayashi Imori of Bastion Systems (the original developer
of this plugin) in early June 2010 and is attached to this email -
thanks Daniel. The Squirrelmail team has not yet made it to update this
plugin in their repository:

So this is the first public release I am aware of.

Thanks for reading,

Moritz Naumann
Naumann IT Security Consulting
Samariterstr. 16
10247 Berlin

Attachment: vkeyboard-0.9.2-1.4.0.tar.gz

Attachment: vkeyboard-0.9.2-1.4.0.tar.gz.gpg

Attachment: vkeyboard-0.9.2-1.4.0.tar.gz.sha512

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]