CKFinder 2.3 & FCKEditor 2.6.8 SWF Cross Site Scripting

2012.11.13
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

The latest versions of CKFinder (2.3) and FCKEditor(2.6.8) are accepting SWF as a valid extension. As a result, it is possible to make a website vulnerable to an XSS attack by uploading a malicious SWF file. Source:http://soroush.secproject.com/blog/2012/11/xss-by-uploadingincluding-a-swf-file/ This has been reported to the vendor today, but the swf file is public currently via my blog. PoC: Demo Link:http://ckfinder.com/demo Result: http://ckfinder.com/userfiles/flash/Public%20Folder/XSSProject.swf?js=alert(document.domain) Regards Soroush Dalili

References:

http://ckfinder.com/demo
http://soroush.secproject.com/blog/2012/11/xss-by-uploadingincluding-a-swf-file/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top