Advertisement






CKFinder 2.3 & FCKEditor 2.6.8 SWF Cross Site Scripting

CVE Category Price Severity
N/A CWE-79 N/A Medium
Author Risk Exploitation Type Date
Unknown High Remote 2012-11-13
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2012110075

Below is a copy:

The latest versions of CKFinder (2.3) and FCKEditor(2.6.8) are accepting SWF as a valid extension. As a result, it is possible to make a website vulnerable to an XSS attack by uploading a malicious SWF file.
Source:http://soroush.secproject.com/blog/2012/11/xss-by-uploadingincluding-a-swf-file/

This has been reported to the vendor today, but the swf file is public currently via my blog.

PoC:
Demo Link:http://ckfinder.com/demo
Result: http://ckfinder.com/userfiles/flash/Public%20Folder/XSSProject.swf?js=alert(document.domain)


Regards
Soroush Dalili


Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.