Yappa-NG Unspecified Cross-Site Scripting Vulnerability
BID:13372
Info
Yappa-NG Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 13372 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2005 12:00AM |
| Updated: | Apr 24 2005 12:00AM |
| Credit: | Discovery is credited to James Bercegay of the GulfTech Security Research Team. |
| Vulnerable: |
yappa-ng yappa-ng 2.3.1 yappa-ng yappa-ng 2.3 .0 yappa-ng yappa-ng 2.2.2 yappa-ng yappa-ng 2.2.1 yappa-ng yappa-ng 2.2 .0 yappa-ng yappa-ng 2.1 .0 yappa-ng yappa-ng 2.0.1 yappa-ng yappa-ng 2.0 .0 yappa-ng yappa-ng 1.6 yappa-ng yappa-ng 1.5 yappa-ng yappa-ng 1.4 yappa-ng yappa-ng 1.3 yappa-ng yappa-ng 1.2 yappa-ng yappa-ng 1.1 yappa-ng yappa-ng 1.0 yappa-ng yappa-ng 0.9 |
| Not Vulnerable: |
yappa-ng yappa-ng 2.3.2 |
Discussion
Yappa-NG Unspecified Cross-Site Scripting Vulnerability
yappa-ng is prone to an unspecified cross-site scripting vulnerability. This issue may allow for theft of cookie-based authentication credentials or other attacks.
The vendor has not published any specific details about this vulnerability other than stating that it is addressed in the 2.3.2 security release of the software.
yappa-ng is prone to an unspecified cross-site scripting vulnerability. This issue may allow for theft of cookie-based authentication credentials or other attacks.
The vendor has not published any specific details about this vulnerability other than stating that it is addressed in the 2.3.2 security release of the software.
Exploit / POC
Yappa-NG Unspecified Cross-Site Scripting Vulnerability
There is no exploit required.
The following proof of concept URI are available:
http://www.example.com/admin_modules/admin_module_info.inc.php?lang_akt[admin_ainfo_hmain]=[XSS]
http://www.example.com/src/index_footer-copyright.inc.php?config[release]=[XSS]
http://www.example.com/src/index_thumbs.inc.php?page[thumb_table_width]=[XSS]
There is no exploit required.
The following proof of concept URI are available:
http://www.example.com/admin_modules/admin_module_info.inc.php?lang_akt[admin_ainfo_hmain]=[XSS]
http://www.example.com/src/index_footer-copyright.inc.php?config[release]=[XSS]
http://www.example.com/src/index_thumbs.inc.php?page[thumb_table_width]=[XSS]
Solution / Fix
Yappa-NG Unspecified Cross-Site Scripting Vulnerability
Solution:
This issue has been addressed in the 2.3.2 security release of the software.
yappa-ng yappa-ng 0.9
yappa-ng yappa-ng 1.0
yappa-ng yappa-ng 1.1
yappa-ng yappa-ng 1.2
yappa-ng yappa-ng 1.3
yappa-ng yappa-ng 1.4
yappa-ng yappa-ng 1.5
yappa-ng yappa-ng 1.6
yappa-ng yappa-ng 2.0 .0
yappa-ng yappa-ng 2.0.1
yappa-ng yappa-ng 2.1 .0
yappa-ng yappa-ng 2.2 .0
yappa-ng yappa-ng 2.2.1
yappa-ng yappa-ng 2.2.2
yappa-ng yappa-ng 2.3 .0
yappa-ng yappa-ng 2.3.1
Solution:
This issue has been addressed in the 2.3.2 security release of the software.
yappa-ng yappa-ng 0.9
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 1.0
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 1.1
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 1.2
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 1.3
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 1.4
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 1.5
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 1.6
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.0 .0
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.0.1
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.1 .0
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.2 .0
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.2.1
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.2.2
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.3 .0
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
yappa-ng yappa-ng 2.3.1
-
yappa-ng yappa-ng 2.3.2
http://sourceforge.net/project/showfiles.php?group_id=70802
References
Yappa-NG Unspecified Cross-Site Scripting Vulnerability
References:
References:
- 2.3.2 Security Release (yappa-ng)
- Vendor Homepage (In-Portal)
- Yappa-NG Multiple Vulnerabilities (GulfTech Security Research
)