Document Title: =============== Freenet SMS Service - Persistent Web Vulnerability Release Date: ============= 2011-08-02 Vulnerability Laboratory ID (VL-ID): ==================================== 123 Abstract Advisory Information: ============================== An anonymous laboratory researcher discovered a persistent input validation vulnerability on the SMS Service & Adressbook of Freenet. Vulnerability Disclosure Timeline: ================================== 2011-02-09: Vendor Notification 2011-05-04: Vendor Response/Feedback 2011-07-01: Vendor Fix/Patch 2011-08-03: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ An persistent input validation vulnerability is detected on the Freenet - SMS Service & Adressbook. Remote attackers can implement over the sms & adressbook module malicious persistent script codes. The successful exploitation of the vulnerability allows an remote attacker to hijack account sessions cia adressbook exchange & can lead to persistent content request manipulation. Vulnerable Module(s): [+] Adressbook & SMS Topic Pictures: ../sms1.png Proof of Concept (PoC): ======================= This Vulnerabilities can be exploited by remote attackers with low user inter action. For demonstration or reproduce ... Manually reproduce ... 1. Login to the EMail Service 2. Switch to SMS & create a new SMS 3. Include malicious code in the topic. For example: iframe or reloop. 4. Click on the Banner or switch to send & the malicious code will be send or executed PoC: >"