09.28.35 Cross-Site Scripting vulnerability in 3D Cloud for Joomla | |
Hello Bugtraq! I want to warn you about Cross-Site Scripting vulnerability in 3D Cloud (mod_3dcloud) plugin for Joomla. Which I found and disclosed at 22.01.2010. It is similar to XSS vulnerability in JVClouds3D for Joomla (http://websecurity.com.ua/ tagcloud.swf which are vulnerable to XSS attacks I mentioned in my article XSS vulnerabilities in 34 millions flash files (http://www.webappsec.org/ XSS: http://site/modules/mod_ Code will execute after click. It's strictly social XSS. Also it's possible to conduct HTML Injection attack, including in those flash files which have protection (in flash files or via WAF) against javascript and vbscript URI in parameter tagcloud. HTML Injection: http://site/modules/mod_ Vulnerable are 3D Cloud 1.3 and previous versions. I mentioned about this vulnerability at my site (http://websecurity.com.ua/ Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua | |
|
Total comments: 0 | |