JAWS Glossary Cross-Site Scripting Vulnerability
BID:13796
Info
JAWS Glossary Cross-Site Scripting Vulnerability
| Bugtraq ID: | 13796 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2005 12:00AM |
| Updated: | May 28 2005 12:00AM |
| Credit: | Discovery is credited to Nah <[email protected]>. |
| Vulnerable: |
JAWS JAWS 0.5.1 JAWS JAWS 0.5 beta2 JAWS JAWS 0.5 JAWS JAWS 0.4 |
| Not Vulnerable: | |
Discussion
JAWS Glossary Cross-Site Scripting Vulnerability
JAWS is prone to a cross-site scripting vulnerability.
This issue is due to a failure in the application to properly sanitize user-supplied input to the 'Glossary' module.
This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
JAWS versions 0.4 and 0.5 and subsequent are reportedly vulnerable.
JAWS is prone to a cross-site scripting vulnerability.
This issue is due to a failure in the application to properly sanitize user-supplied input to the 'Glossary' module.
This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
JAWS versions 0.4 and 0.5 and subsequent are reportedly vulnerable.
Exploit / POC
JAWS Glossary Cross-Site Scripting Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/index.php?gadget=Glossary&action=ViewTerm&term=<script
src=some script</script>
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/index.php?gadget=Glossary&action=ViewTerm&term=<script
src=some script</script>
Solution / Fix
JAWS Glossary Cross-Site Scripting Vulnerability
Solution:
A fix to address this issue is available in the cvs repository version.
Solution:
A fix to address this issue is available in the cvs repository version.