Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] feedreader3 has XSS vulnerability |
|---|---|
| Date: | Sun, 30 Sep 2007 15:26:44 +0200 |
Hi, This is a cross-zone scripting vulnerability. FeedReader uses the IE browser control to render HTML. The RSS reader converts the RSS item data to a formatted HTML file and caches it locally. When the user clicks on the RSS item, the RSS reader displays the local cached file, and any script in that file (or external references) will run in Local Zone. Therefore, an attacker can create/manipulate an RSS feed that will execute arbitrary code on the user's machine. Btw, according to Bugtrag (http://www.securityfocus.com/bid/25849/exploit) an attacker must convince the victim into subscribing a malicious RSS feed. As I've already discussed this in my blog post (http://aviv.raffon.net/2007/08/16/VistaGadgetsGoneWild.aspx) regarding the Windows Vista's RSS gadget, this claim is not true. In today's Web2.0 era, if a remote code execution vulnerability exists in RSS readers, it is very easy to create an RSS based worm. --Aviv. -----Original Message----- From: Guy Mizrahi [mailto:guy@hacking.org.il] Sent: Friday, September 28, 2007 3:02 PM To: bugtraq@securityfocus.com Subject: feedreader3 has XSS vulnerability Hello, I have found that feedreader3 has XSS vulnerability in its internal browser. When I post a script into wordpress( like <script>alert("XSS")</script>, the RSS feed in the internal browser is vulnerable and show an alert box. POC movie here: http://www.hacking.org.il/demos/feedreader3.wmv Guy Mizrahi (ZuLL) Hebrew blog: http://www.hacking.org.il _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Public Media Manager <= 1.3 Remote File Inclusion Vulnerability, 0in . email |
|---|---|
| Next by Date: | [Full-disclosure] [ GLSA 200709-18 ] Bugzilla: Multiple vulnerabilities, Raphael Marichez |
| Previous by Thread: | feedreader3 has XSS vulnerability, Guy Mizrahi |
| Next by Thread: | Re: 0trace - traceroute on established connections, tyter9 |
| Indexes: | [Date] [Thread] [Top] [All Lists] |