Blosxom Writeback Plug-in HTML Injection Vulnerability
BID:10488
Info
Blosxom Writeback Plug-in HTML Injection Vulnerability
| Bugtraq ID: | 10488 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2004 12:00AM |
| Updated: | Jun 08 2004 12:00AM |
| Credit: | Discovery is credited to kylem <[email protected]>. |
| Vulnerable: |
Blosxom Blosxom 2.0 |
| Not Vulnerable: | |
Discussion
Blosxom Writeback Plug-in HTML Injection Vulnerability
Blosxom is prone to an HTML injection vulnerability. This issue presents itself when Blosxom is used in combination with the 'writeback' plug-in.
This can allow an attacker to inject HTML and script code when posting comments on a vulnerable site. A successful attack can allow an attacker to steal cookie-based authentication credentials. Other attacks are possible as well.
Blosxom version 2.0 is affected by this issue, however, other versions could be vulnerable as well.
Blosxom is prone to an HTML injection vulnerability. This issue presents itself when Blosxom is used in combination with the 'writeback' plug-in.
This can allow an attacker to inject HTML and script code when posting comments on a vulnerable site. A successful attack can allow an attacker to steal cookie-based authentication credentials. Other attacks are possible as well.
Blosxom version 2.0 is affected by this issue, however, other versions could be vulnerable as well.
Exploit / POC
Blosxom Writeback Plug-in HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Blosxom Writeback Plug-in HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Blosxom Writeback Plug-in HTML Injection Vulnerability
References:
References:
- Blosxom Homepage (Blosxom)
- Re: [blosxom] XSS in writeback (Ivan Grynov)
- KM-2004-01: Cross-Site Scripting in Blosxom writeback (Kyle Maxwell
)