<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nGenuity Information Services &#187; Software as a Service</title>
	<atom:link href="http://www.ngenuity.org/wordpress/category/security/software-as-a-service/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ngenuity.org/wordpress</link>
	<description>Security for the A.D.D generation</description>
	<lastBuildDate>Wed, 10 Mar 2010 19:25:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>NGENUITY-2009-004 &#8211; ChamberMaster Forgot Password Reflected Cross-Site Scripting</title>
		<link>http://www.ngenuity.org/wordpress/2009/02/06/ngenuity-2009-004-chambermaster-forgot-password-reflected-cross-site-scripting/</link>
		<comments>http://www.ngenuity.org/wordpress/2009/02/06/ngenuity-2009-004-chambermaster-forgot-password-reflected-cross-site-scripting/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 17:09:39 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Software as a Service]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[ChamberMaster]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=178</guid>
		<description><![CDATA[nGenuity Information Services &#8211; Security Advisory
   Advisory ID: NGENUITY-2009-004 - ChamberMaster Forgot Password Reflected Cross-Site Scripting
   Application: ChamberMaster.com
        Vendor: ChamberMaster, INC
Vendor website: http://www.chambermaster.com
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     ChamberMaster is a hosted web application that is designed [...]]]></description>
			<content:encoded><![CDATA[<p>nGenuity Information Services &#8211; Security Advisory</p>
<pre>   Advisory ID: NGENUITY-2009-004 - ChamberMaster Forgot Password Reflected Cross-Site Scripting
   Application: ChamberMaster.com
        Vendor: ChamberMaster, INC
Vendor website: <a href="http://www.chambermaster.com  " target="_blank">http://www.chambermaster.com</a>
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     ChamberMaster is a hosted web application that is designed to manage
various aspects of chamber of commerce operations. 

 II. DETAILS
     The ChamberMaster hosted application is vulnerable to a reflected
cross-site scripting vulnerability. This attack can be used to display
content or execute malicious JavaScript in the context of the victims
web browser.

Attack Scenario:
1. The attacker sends or places links, similar to the one below. These could be
   delivered via instant message, social network, email or any other medium
   in which a link can be provided to an end user.
   Example URL</pre>
<pre>     <span class="moz-txt-link-freetext">/directory/jsp/admin/login/ForgotPwd.jsp?email=INSERTXSSHERE</span>

2. Victim clicks on link.
3. Victims browser executes malicious code. 

From this attack, the attacker now controls the victims browser.
They can access and manipulate data that users ChamberMaster session has access
too.

III. REFERENCES
     [1] - http://www.chambermaster.com

 IV. VENDOR COMMUNICATION
     2.3.2009 - Vendor Notified
     2.6.2009 - Notification from vendor that this issue has been fixed.

Copyright (c) 2008 nGenuity Information Services, LLC</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2009/02/06/ngenuity-2009-004-chambermaster-forgot-password-reflected-cross-site-scripting/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
