Document Title: =============== RTL TV Website - Persistent Service Vulnerabilities Release Date: ============= 2011-08-27 Vulnerability Laboratory ID (VL-ID): ==================================== 257 Product & Service Introduction: =============================== RTL Television (formerly RTL plus) is a German commercial television station distributed via cable and satellite along with DVB-T (Digital Video Broadcasting – Terrestrial), in larger population centres. It belongs to the RTL Group and is, in terms of market share, Germany`s largest private free-to-air broadcaster. (Copy of the Vendor Homepage: http://en.wikipedia.org/wiki/RTL_Television) Abstract Advisory Information: ============================== A Vulnerability-Lab researcher discovered multiple persistent HTML/Javascript injection vulnerabilities for RTL TV vendor website. Vulnerability Disclosure Timeline: ================================== 2011-05-25: Vendor Notification 2011-**-**: Vendor Response/Feedback 2011-08-27: Vendor Fix/Patch 2011-08-27: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ A persistent input validation vulnerability is detected on RTL Commnunity Page. The vulnerability allows an remote attacker to implement/inject malicious persistent script code over the input fields -group_name and -description. The successfully exploitation of the vulnerability allows an attacker to hijack customer sessions or can lead to malicous persistent script code execution on application-side. Vulnerable Module(s): [+] Group Title Input Field [+] Group Description Input Field Affected: [+] Newest Group View [+] Profile Groups Pictures: ../1.png ../2.png Proof of Concept (PoC): ======================= The vulnerability can be exploited by low level user accounts on the application system. For demonstration or reproduce ... 1.1