header-logo
Suggest Exploit
vendor:
XODA Document Management System
by:
Shai rod
8,8
CVSS
HIGH
Stored XSS & Arbitrary File Upload
79
CWE
Product Name: XODA Document Management System
Affected Version From: 0.4.5
Affected Version To: 0.4.5
Patch Exists: YES
Related CWE: N/A
CPE: a:xoda:xoda
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012

XODA Document Management System Stored XSS & Arbitrary File Upload Vulnerability

It is possible to access the file upload page '?upload_to=' without the need to authenticate (log in) to the XODA system. An attacker is able to upload a web shell to the server and gain unauzhorized access to the operating system. For the stored XSS, an attacker can enter a malicious payload in the file description or filters field and when the page is reloaded, the XSS will be triggered.

Mitigation:

Ensure that the application is updated to the latest version and that all security patches are applied. Restrict access to the file upload page and ensure that only authenticated users are allowed to upload files.
Source

Exploit-DB raw data:

# Exploit Title: XODA Document Management System Stored XSS & Arbitrary File Upload Vulnerability.
# Date: 21/08/2012
# Exploit Author: Shai rod (@NightRang3r)
# Vendor Homepage: http://xoda.org/
# Software Link: http://sourceforge.net/projects/xoda/files/xoda/xoda-0.4.5/
# Version: 0.4.5
 
#Gr33Tz: @aviadgolan , @benhayak, @nirgoldshlager, @roni_bachar


About the Application:
======================

XODA targets the end-user allowing organizing of documents in a professional manner.


Vulnerability Description
=========================

1. Arbitrary File Upload:

It is possible to access the file upload page "?upload_to=" without the need to authenticate (log in) to the XODA system.
An attacker is able to upload a web shell to the server and gain unauzhorized access to the operating system.

Vulnerable URL: http://server/xodadir/?upload_to=

Default location of uploaded files: http://server/xodadir/files/


2. Stored XSS in file description.

Steps to reproduce the XSS:

2.1 Select a document.
2.2 Click on description.
2.3 Enter XSS Payload: <img src='1.jpg'onerror=javascript:alert(document.cookie)>
2.4 Reload the page XSS Should be triggered.

3. Stored XSS in filters.

Steps to reproduce the XSS:

3.1 Select the document.
3.2 Click on filters.
3.3 In the "Filters (one per line):" field insert XSS paload: <img src='1.jpg'onerror=javascript:alert(document.cookie)>
3.4 Click "Set filters".
3.5 Click on the document icon to open its properties.
3.6 XSS Should be triggered.