Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
BID:11803
Info
Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
| Bugtraq ID: | 11803 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2004 12:00AM |
| Updated: | Dec 03 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
Apache Apache Lucene 1.4.2 |
| Not Vulnerable: |
Apache Apache Lucene 1.4.3 |
Discussion
Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
It is reported that Jakarta Lucene is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link is followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability is reported to exist in version 1.4.2 and previous of Jakarta Lucene. Other versions may also be affected.
It is reported that Jakarta Lucene is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link is followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability is reported to exist in version 1.4.2 and previous of Jakarta Lucene. Other versions may also be affected.
Exploit / POC
Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
Solution:
The vendor has released an update to address this vulnerability:
Apache Apache Lucene 1.4.2
Solution:
The vendor has released an update to address this vulnerability:
Apache Apache Lucene 1.4.2
-
Apache Software Foundation Jakarta Lucene 1.4.3
http://www.apache.org/dyn/closer.cgi/jakarta/lucene/
References
Apache Jakarta Results.JSP Remote Cross-Site Scripting Vulnerability
References:
References:
- Jakarta Lucene Homepage (Apache Software Foundation)