SafeHTML Multiple HTML Entity Bypass Vulnerabilities
BID:12692
Info
SafeHTML Multiple HTML Entity Bypass Vulnerabilities
| Bugtraq ID: | 12692 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2005 12:00AM |
| Updated: | Feb 28 2005 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
SafeHTML SafeHTML 1.2.1 SafeHTML SafeHTML 1.2 SafeHTML SafeHTML 1.1 |
| Not Vulnerable: |
SafeHTML SafeHTML 1.3.1 SafeHTML SafeHTML 1.3 |
Discussion
SafeHTML Multiple HTML Entity Bypass Vulnerabilities
It is reported that SafeHTML does not filter HTML entities in a proper manner. The application is reported prone to two input validation vulnerabilities.
Failure to filter HTML content can result in the exploitation of various latent vulnerabilities in Web based applications. A successful attack may facilitate HTML injection or cross-site scripting type issues.
SafeHTML versions prior to 1.3.0 are affected by these issues.
It is reported that SafeHTML does not filter HTML entities in a proper manner. The application is reported prone to two input validation vulnerabilities.
Failure to filter HTML content can result in the exploitation of various latent vulnerabilities in Web based applications. A successful attack may facilitate HTML injection or cross-site scripting type issues.
SafeHTML versions prior to 1.3.0 are affected by these issues.
Exploit / POC
SafeHTML Multiple HTML Entity Bypass Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
SafeHTML Multiple HTML Entity Bypass Vulnerabilities
Solution:
SafeHTML 1.3.0 and subsequent versions are not vulnerable to these issues.
SafeHTML SafeHTML 1.1
SafeHTML SafeHTML 1.2
SafeHTML SafeHTML 1.2.1
Solution:
SafeHTML 1.3.0 and subsequent versions are not vulnerable to these issues.
SafeHTML SafeHTML 1.1
-
SafeHTML safehtml-1.3.1.zip
http://pixel-apes.com/download/safehtml-1.3.1.zip
SafeHTML SafeHTML 1.2
-
SafeHTML safehtml-1.3.1.zip
http://pixel-apes.com/download/safehtml-1.3.1.zip
SafeHTML SafeHTML 1.2.1
-
SafeHTML safehtml-1.3.1.zip
http://pixel-apes.com/download/safehtml-1.3.1.zip