# Exploit Title: jBilling 3.0.2 Cross Site Scripting Vulnerability # Date: 11/23/2012 # Exploit Author: Woody Hughes # Vendor Homepage: http://www.jbilling.com # Software Link: http://sourceforge.net/projects/jbilling/files/latest/download # Version: 3.0.2 # Tested on: Ubuntu Linux INGRESS SECURITY SECURITY ADVISORY INGRES-11232012-jBilling 3.0.2 Cross Site Scripting Vulnerability November 23, 2012 OVERVIEW Ingress Security has found a cross site scripting vulnerability in the form of a cross site request forgery in the jBilling billing software. jBilling's mission is to provide a robust, secure, open source alternative for enterprise billing. With our world-class service team, we help companies all over the world deploy and maintain billing solutions to meet their business needs. AFFECTED PRODUCTS jBilling 3.0.2 PLATFORM: Linux LOCAL/REMOTE: Remote CVSS SCORE: 3.7 (AV:R/AC:L/Au:R/C:C/I:P/A:N/B:/E:P/RL:U/RC:U) DESCRIPTION OF VULNERABILITIES Cross Site Request Forgery (CSRF) jBilling does not properly check user input, thus allowing the