ModernBill orderwiz.php script cross-site scripting
| modernbill-orderwiz-xss (20035) |
Description:
ModernBill is vulnerable to cross-site scripting, caused by improper validation of user-supplied input in the c_code and aid parameters. A remote attacker could embed malicious script in the c_code and aid parameters in a URL request to the orderwiz.php script which, once the link is clicked, would be executed in the victim's Web browser within the security context of the hosting site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Consequences:
Gain Access
Remedy:
Upgrade to the latest version of ModernBill (4.3.1 or later), when it becomes available from the ModernBill Web site. See References.
References:
- GulfTech Research and Development, April 10th, 2005: Multiple ModernBill 4.3.0 And Earlier Vulnerabilities.
- ModernBill Web site: Web Host Billing Software.
- BID-13087: ModernGigabyte ModernBill C_CODE Parameter Cross-Site Scripting Vulnerability
- BID-13089: ModernGigabyte ModernBill Aid Parameter Cross-Site Scripting Vulnerability
- CVE-2005-1053: Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.
- OSVDB ID: 15426: ModernBill orderwiz.php Multiple Variable XSS
- SA14890: ModernBill Cross-Site Scripting and File Inclusion Vulnerabilities
- SECTRACK ID: 1013672: ModernBill Include File Error in Sample `news.php` Script Lets Remote Users Execute Commands and Input Validation Holes in `orderwiz.php` Permit Cross-Site Scripting Attacks
Platforms Affected:
- ModernBill ModernBill 4.3.0 and prior
Reported:
Apr 11, 2005
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
