Page 1 of 1
Script in comments
Posted: Mon Dec 25, 2006 10:36 pm
by sanjay
On one of my sites, some one by this name "L0j1k" left a comment and a script
alert('test')
that opens a popup with "test" when you open the page.
This person mentions the vulnerability here:
http://www.l0j1k.com/LoFiPages/mainPage.php
Re: Script in comments
Posted: Mon Dec 25, 2006 11:50 pm
by Elijah Lofgren
I got the same thing. Ted is working on releasing a new version of Comments to fix this. I had added the ability to disable HTML in Comments SVN. Looks like we'll need to turn that on or make sure that JS gets removed by default.
Re: Script in comments
Posted: Tue Dec 26, 2006 12:35 am
by Elijah Lofgren
Attached is a fixed version of Comments. It will disable HTML in comments by default (and upgrades) which will remove the XSS vulnerability.
Ted should formally release Comments 1.8.0 soon.
Elijah
[gelöscht durch Administrator]
Re: Script in comments
Posted: Tue Dec 26, 2006 2:08 am
by L0j1k
Hello. For the record, I notified Ted Kulp of this problem via email as soon as I had confirmed it. I have reported it to Bugtraq as of this afternoon, but only after having confirmed with Ted that a fix was made and awaiting publication (I made sure to miss the publication deadline for today seeing as how it's the holiday and I wanted to give as much time to the developers as possible to publish the fix).
To sanjay, I would like to apologize for putting the XSS on your site. Where I could, I tried to put it in a reply to a user comment so that it wouldn't appear on the main page, rather on the separate page for replies to user comments.
I have listed my full (albeit simple) report at:
http://www.L0j1k.com/securityCMSMadeSim ... 5Dec06.txt
Merry Christmas, everyone. And a happy New Year, and Kwanzaa or whatever.
Re: Script in comments
Posted: Mon Apr 16, 2007 4:15 pm
by forgot
Elijah Lofgren, you have to admit he is a funny guy after all. Looks inoffensive to me. He found you even here. LOL
Re: Script in comments
Posted: Wed Jan 23, 2008 12:41 am
by johannabartley
The
Nouveau Riche University forum is filled with these scripts. Ain't there anything we can do to get rid of them?