Document Title:
===============
Microsoft Fitbie Service - Multiple Cross Site Vulnerabilities
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=573
Release Date:
=============
2012-06-16
Vulnerability Laboratory ID (VL-ID):
====================================
573
Common Vulnerability Scoring System:
====================================
2.3
Product & Service Introduction:
===============================
Official Microsoft (msn) Fitbie service web application.
URL: http://fitbie.msn.com/
Abstract Advisory Information:
==============================
The Vulnerability Laboratory Research team discovered multiple client side Web Vulnerabilities in Microsofts Fitbie web application service.
Vulnerability Disclosure Timeline:
==================================
2012-05-13: Researcher Notification & Coordination
2012-05-15: Vendor Notification
2012-05-16: Vendor Response/Feedback
2012-06-15: Vendor Fix/Patch
2012-06-17: Public or Non-Public Disclosure
Discovery Status:
=================
Published
Exploitation Technique:
=======================
Remote
Severity Level:
===============
Low
Technical Details & Description:
================================
Multiple non-persistent cross site scripting vulnerabilities are detected in Microsofts Fitbie web service application.
The vulnerability allows remote attackers to hijack website customer, moderator & admin sessions with medium or high
required user inter action or local low privileged user account and low user inter action. Successful exploitation
can result in account steal, phishing & client-side content request manipulation. Exploitation requires low user inter action.
The first vulnerability is located in the newsletter module with the vulnerable bound parameters mail & callback.
The second vulnerability is located in the destination module with the vulnerable bound parameters memvers profile name.
Vulnerable Module(s):
[+] Newsletter - Mail & Callback
[+] Destination - Member Profile
Proof of Concept (PoC):
=======================
The validation vulnerabilities can be exploited by remote attackers with medium required user inter action.
For demonstration or reproduce ...
Review: EMail