Document Title: =============== Mail.RU Group eMail - Persistent Web Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=709 Release Date: ============= 2012-10-09 Vulnerability Laboratory ID (VL-ID): ==================================== 709 Common Vulnerability Scoring System: ==================================== 3.1 Product & Service Introduction: =============================== Digital Sky Technologies (DST) is an international investment firm focused solely on the Internet sector. The firm was founded by Yuri Milner and emerged out of Mail.ru Group. Today, DST is fully independent of Mail.ru Group and its investments include Facebook, Zynga and Groupon. (Copy of the Homepage: http://en.wikipedia.org/wiki/Mail.ru_Group ) Abstract Advisory Information: ============================== The Vulnerability Laboratory Research Team discovered a Web Vulnerability in the official Mail.RU Group website service application. Vulnerability Disclosure Timeline: ================================== 2012-09-26: Researcher Notification & Coordination 2012-09-27: Vendor Notification 2012-10-09: Public or Non-Public Disclosure Discovery Status: ================= Published Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ A persistent web vulnerability is detected in the official Mail.RU Group website service application. The bug allows remote attackers with low privileges to inject via editor own malicious persistent script codes on application-side. The vulnerability is located in the editor module (compose function) with the bound vulnerable add link parameters. The bug can be exploited by remote attackers when processing to load or compose (draft,incoming & co.) malicious messages. Remote attackers can compose malicious messages to hijack admin/moderator/customer accounts of the yandex mail.ru service. Successful exploitation result in persistent web context manipulation, client side phishing or persistent session hijacking via messages. Vulnerable Service(s): [+] Mail.RU Group Vulnerable Section(s): [+] Editor - Compose Message Vulnerable Module(s): [+] Add Link Vulnerable Parameter(s): [+] Message - Name & URL Proof of Concept (PoC): ======================= The persistent vulnerability can be exploited by remote attackers with low privileged mail account and with low or medium required user inter action. For demonstration or reproduce ... Review: Editor - Add Link - URL & NAME
darisu is der k?nig und findet es <[PERSISTENT MALICIOUS SCRIPT CODE!])" <.com" ="">sehr gut "><[PERSISTENT MALICIOUS SCRIPT CODE!]) <_





TEST! TEST <[PERSISTENT MALICIOUS SCRIPT CODE!]")" <.com"="">TES"><[PERSISTENT MALICIOUS SCRIPT CODE!]") <

PoC: Link as URL http://">