Multiple Bluemoon, Inc. modules for XOOPS unspecified cross-site scripting

bluemoon-unspecified-xss (42072) The risk level is classified as MediumMedium Risk

Description:

Multiple Bluemoon inc. modules for XOOPS are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using an unspecified parameter in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

Platforms Affected:

  • Bluemoon, BackPack module for XOOPS 0.91
  • Bluemoon, BmSurvey module for XOOPS 0.84
  • Bluemoon, newbb_fileup module for XOOPS 1.83
  • Bluemoon, News_embed module for XOOPS 1.44
  • Bluemoon, PopnupBlog for XOOPS 3.19

Remedy:

For BackPack:
Upgrade to the latest version of BackPack (0.93 or later), available from the Bluemoon XOOPS Web site. See References.

For BmSurvey:
Upgrade to the latest version of BmSurvey (0.85 or later), available from the Bluemoon XOOPS Web site. See References.

For newbb_fileup:
Upgrade to the latest version of newbb_fileup (1.84 or later), available from the Bluemoon XOOPS Web site. See References.

For News_embed:
Upgrade to the latest version of News_embed (1.45 or later), available from the Bluemoon XOOPS Web site. See References.

For PopnupBlog:
Upgrade to the latest version of PopnupBlog (3.20 or later), available from the Bluemoon XOOPS Web site. See References.

Consequences:

Gain Access

References:

  • Bluemoon XOOPS Security Advisory, 2008-4-28 15:00:00, XOOPS: Security Update Information at http://www.bluemooninc.biz/~xoops/modules/news/article.php?storyid=69.
  • Bluemoon XOOPS Web site, Downloads at http://www.bluemooninc.biz/~xoops2/modules/mydownloads/.
  • BID-28966: Multiple Bluemoon inc. Modules for XOOPS Unspecified Cross Site Scripting Vulnerabilities
  • CVE-2008-2035: Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
  • SA29993: XOOPS Various Bluemoon inc. Modules Cross-Site Scripting

Reported:

Apr 28, 2008

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page