CVSTrac Unspecified Cross-Site Scripting Vulnerability
BID:12017
Info
CVSTrac Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 12017 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1146 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Michael Krax disclosed this vulnerability. |
| Vulnerable: |
OpenPKG OpenPKG 2.2 OpenPKG OpenPKG 2.1 OpenPKG OpenPKG Current CVSTrac CVSTrac 1.1.4 CVSTrac CVSTrac 1.1.3 CVSTrac CVSTrac 1.1.2 CVSTrac CVSTrac 1.1.1 CVSTrac CVSTrac 1.1 |
| Not Vulnerable: |
CVSTrac CVSTrac 1.1.5 |
Discussion
CVSTrac Unspecified Cross-Site Scripting Vulnerability
CVSTrac is reported susceptible to an unspecified cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI data prior to including it in dynamically generated web page content.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability is reported to exist in versions prior to 1.1.5 of CVSTrac.
CVSTrac is reported susceptible to an unspecified cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI data prior to including it in dynamically generated web page content.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
This vulnerability is reported to exist in versions prior to 1.1.5 of CVSTrac.
Exploit / POC
CVSTrac Unspecified Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
CVSTrac Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released version 1.1.5 of the application to resolve this issue.
OpenPKG has released advisory OpenPKG-SA-2004.056 to address this issue. Please see the referenced advisory for further information.
CVSTrac CVSTrac 1.1
CVSTrac CVSTrac 1.1.1
CVSTrac CVSTrac 1.1.2
CVSTrac CVSTrac 1.1.3
CVSTrac CVSTrac 1.1.4
Solution:
The vendor has released version 1.1.5 of the application to resolve this issue.
OpenPKG has released advisory OpenPKG-SA-2004.056 to address this issue. Please see the referenced advisory for further information.
CVSTrac CVSTrac 1.1
-
CVSTrac cvstrac-src-1.1.5.tar.gz
http://www.cvstrac.org/cvstrac-src-1.1.5.tar.gz
CVSTrac CVSTrac 1.1.1
-
CVSTrac cvstrac-src-1.1.5.tar.gz
http://www.cvstrac.org/cvstrac-src-1.1.5.tar.gz
CVSTrac CVSTrac 1.1.2
-
CVSTrac cvstrac-src-1.1.5.tar.gz
http://www.cvstrac.org/cvstrac-src-1.1.5.tar.gz
CVSTrac CVSTrac 1.1.3
-
CVSTrac cvstrac-src-1.1.5.tar.gz
http://www.cvstrac.org/cvstrac-src-1.1.5.tar.gz
CVSTrac CVSTrac 1.1.4
-
CVSTrac cvstrac-src-1.1.5.tar.gz
http://www.cvstrac.org/cvstrac-src-1.1.5.tar.gz
References
CVSTrac Unspecified Cross-Site Scripting Vulnerability
References:
References:
- cvstrac - Timeline (CVSTrac)
- Product Home Page (CVSTrac)