Document Title:
===============
RTL TV Website - Persistent Service Vulnerabilities
Release Date:
=============
2011-08-27
Vulnerability Laboratory ID (VL-ID):
====================================
257
Product & Service Introduction:
===============================
RTL Television (formerly RTL plus) is a German commercial television station distributed
via cable and satellite along with DVB-T (Digital Video Broadcasting – Terrestrial), in
larger population centres. It belongs to the RTL Group and is, in terms of market share,
Germany`s largest private free-to-air broadcaster.
(Copy of the Vendor Homepage: http://en.wikipedia.org/wiki/RTL_Television)
Abstract Advisory Information:
==============================
A Vulnerability-Lab researcher discovered multiple persistent HTML/Javascript injection vulnerabilities for RTL TV vendor website.
Vulnerability Disclosure Timeline:
==================================
2011-05-25: Vendor Notification
2011-**-**: Vendor Response/Feedback
2011-08-27: Vendor Fix/Patch
2011-08-27: Public or Non-Public Disclosure
Discovery Status:
=================
Published
Affected Product(s):
====================
Exploitation Technique:
=======================
Remote
Severity Level:
===============
Medium
Technical Details & Description:
================================
A persistent input validation vulnerability is detected on RTL Commnunity Page. The vulnerability allows an
remote attacker to implement/inject malicious persistent script code over the input fields -group_name and -description.
The successfully exploitation of the vulnerability allows an attacker to hijack customer sessions or can lead to
malicous persistent script code execution on application-side.
Vulnerable Module(s):
[+] Group Title Input Field
[+] Group Description Input Field
Affected:
[+] Newest Group View
[+] Profile Groups
Pictures:
../1.png
../2.png
Proof of Concept (PoC):
=======================
The vulnerability can be exploited by low level user accounts on the application system. For demonstration or reproduce ...
1.1