PR07-18: Cross-site Scripting (XSS) / HTML injection on Webbler CMS admin login page (1) This advisory has been published following consultation with UK CPNI (formerly known as NISCC) Date Found: 14th June 2007 Successfully tested on: Webbler CMS version 3.1.3. Earlier versions are possibly affected as well. Note: the version number is usually included within 'meta' HTML tags and 'X-Powered-By' HTTP response headers. i.e.: X-Powered-By: webbler version 3.1.3 Description: Webbler CMS is vulnerable to XSS within the "/uploader/index.php" server-side script and 'page' parameter. No authentication is required to exploit this vulnerability. Consequences: An attacker may be able to cause execution of malicious scripting code in the browser of a user who clicks on a link to a site generated/managed by Webbler CMS. HTML tags can also be injected. This type of attack can result in non-persistent defacement of the target site, or the redirection of confidential information to unauthorised third parties. XSS Proof of concept (PoC) URL: http://target-domain.com/uploader/?page= HTML injection PoC URL: http://target-domain.com/uploader/?page=