Plans Display Type Variable Cross-Site Scripting Vulnerability
BID:14069
Info
Plans Display Type Variable Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14069 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2005 12:00AM |
| Updated: | Apr 28 2005 12:00AM |
| Credit: | Credit goes to Nick Waterman ([email protected]) for finding this vulnerability. |
| Vulnerable: |
Plans Plans 6.7.1 |
| Not Vulnerable: |
Plans Plans 6.7.2 |
Discussion
Plans Display Type Variable Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability exists in Plans. An attacker may execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. Successful exploitation could result in theft of cookie-based authentication credentials as well as other attacks.
This issue is reported to affect Plans version 6.7.1; previous versions may also be affected.
A cross-site scripting vulnerability exists in Plans. An attacker may execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. Successful exploitation could result in theft of cookie-based authentication credentials as well as other attacks.
This issue is reported to affect Plans version 6.7.1; previous versions may also be affected.
Exploit / POC
Plans Display Type Variable Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Plans Display Type Variable Cross-Site Scripting Vulnerability
Solution:
Upgrade to the latest version (6.7.2 or higher).
Solution:
Upgrade to the latest version (6.7.2 or higher).