Script in comments

General project discussion. NOT for help questions.
Post Reply
sanjay
Forum Members
Forum Members
Posts: 19
Joined: Fri Oct 15, 2004 7:28 am

Script in comments

Post by sanjay »

On one of my sites, some one by this name "L0j1k" left a comment and a script

alert('test')

that opens a popup with "test" when you open the page.

This person mentions the vulnerability here:

http://www.l0j1k.com/LoFiPages/mainPage.php
User avatar
Elijah Lofgren
Power Poster
Power Poster
Posts: 811
Joined: Mon Apr 24, 2006 1:01 am

Re: Script in comments

Post by Elijah Lofgren »

I got the same thing. Ted is working on releasing a new version of Comments to fix this. I had added the ability to disable HTML in Comments SVN. Looks like we'll need to turn that on or make sure that JS gets removed by default.
Note: I don't have time to take on any more projects. I'm quite busy. I may be too busy to reply to emails or messages. Thanks for your understanding. :)
User avatar
Elijah Lofgren
Power Poster
Power Poster
Posts: 811
Joined: Mon Apr 24, 2006 1:01 am

Re: Script in comments

Post by Elijah Lofgren »

Attached is a fixed version of Comments. It will disable HTML in comments by default (and upgrades) which will remove the XSS vulnerability.

Ted should formally release Comments 1.8.0 soon.

Elijah

[gelöscht durch Administrator]
Note: I don't have time to take on any more projects. I'm quite busy. I may be too busy to reply to emails or messages. Thanks for your understanding. :)
L0j1k

Re: Script in comments

Post by L0j1k »

Hello. For the record, I notified Ted Kulp of this problem via email as soon as I had confirmed it. I have reported it to Bugtraq as of this afternoon, but only after having confirmed with Ted that a fix was made and awaiting publication (I made sure to miss the publication deadline for today seeing as how it's the holiday and I wanted to give as much time to the developers as possible to publish the fix).

To sanjay, I would like to apologize for putting the XSS on your site. Where I could, I tried to put it in a reply to a user comment so that it wouldn't appear on the main page, rather on the separate page for replies to user comments.

I have listed my full (albeit simple) report at:

http://www.L0j1k.com/securityCMSMadeSim ... 5Dec06.txt

Merry Christmas, everyone. And a happy New Year, and Kwanzaa or whatever.
forgot

Re: Script in comments

Post by forgot »

Elijah Lofgren, you have to admit he is a funny guy after all. Looks inoffensive to me. He found you even here. LOL
Last edited by forgot on Mon Apr 16, 2007 4:20 pm, edited 1 time in total.
johannabartley

Re: Script in comments

Post by johannabartley »

The Nouveau Riche University forum is filled with these scripts. Ain't there anything we can do to get rid of them?
Post Reply

Return to “General Discussion”