List Site Pro v2 user account Hijacking vulnerablity

From: StatiX Statix (mail_statixat_private)
Date: Fri Jan 24 2003 - 14:30:10 PST

  • Next message: Michael Bacarella: "MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!"

    List Site Pro v2 user account Hijacking vulnerablity
    Severity:Low
    homepage:http://www.listsitepro.com
    
    
    It is possible to take over another user account by signing up and using | in one of the required feilds.
    List Site Pro uses '|' to delimit the database but the form input is not checked and stripped of them.
    So a user could sign up like this
    username:username
    email:emailat_private
    url:www.url.com
    bannerurl:www.site.com/banner.gif ||password|1036360992|60|468
    banner height:68
    banner width:460
    password:pass
    
    this would take over the account 1036360992 and let the user log in with the password 'password'
    Since the user id is displayed in teh link of the topsite, an attacker could successfully log into whatever 
    account he chooses to. Then the attacker could change the link the banner points to, or any thing else in the account.
    This doesn't give the attacker admin access. But it gives him an opportunity to render the topsite useless.
    
    I contacted the author(s) (http://www.listsitepro.com/) on 11-3-02 and again 12-01-02. no response from either request.
    
    
    StatiX
    mail_statixat_private
    
    
    -- 
    ______________________________________________
    http://www.linuxmail.org/
    Now with e-mail forwarding for only US$5.95/yr
    
    Powered by Outblaze
    



    This archive was generated by hypermail 2b30 : Fri Jan 24 2003 - 18:24:11 PST