WackoWiki TextSearch Cross-Site Scripting Vulnerability
BID:10860
Info
WackoWiki TextSearch Cross-Site Scripting Vulnerability
| Bugtraq ID: | 10860 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2004 12:00AM |
| Updated: | Aug 04 2004 12:00AM |
| Credit: | This vulnerability was announced in a vendor advisory. |
| Vulnerable: |
WackoWiki WackoWiki R3.5 |
| Not Vulnerable: |
WackoWiki WackoWiki R4 |
Discussion
WackoWiki TextSearch Cross-Site Scripting Vulnerability
It is reported that WackoWiki is susceptible to a cross-site scripting vulnerability in its textsearch form. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated web content.
Exploitation of this vulnerability may allow for theft of cookie-based authentication credentials and other attacks.
It is reported that WackoWiki is susceptible to a cross-site scripting vulnerability in its textsearch form. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated web content.
Exploitation of this vulnerability may allow for theft of cookie-based authentication credentials and other attacks.
Exploit / POC
WackoWiki TextSearch Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
WackoWiki TextSearch Cross-Site Scripting Vulnerability
Solution:
The vendor has released an upgrade to address this issue:
WackoWiki WackoWiki R3.5
Solution:
The vendor has released an upgrade to address this issue:
WackoWiki WackoWiki R3.5
-
WackoWiki WackoWiki R4
http://wackowiki.com/WackoDownload/InEnglish
References
WackoWiki TextSearch Cross-Site Scripting Vulnerability
References:
References:
- WackoWiki Release Notes (WackoWiki)