CMSimple Index.PHP Search Cross-Site Scripting Vulnerability
BID:14346
Info
CMSimple Index.PHP Search Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14346 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2005 12:00AM |
| Updated: | Jul 21 2005 12:00AM |
| Credit: | Lostmon is credited with the discovery of this vulnerability. |
| Vulnerable: |
CMSimple Content Management System 2.4 Beta 5 CMSimple Content Management System 2.4 Beta 4 CMSimple Content Management System 2.4 Beta 3 CMSimple Content Management System 2.4 Beta 2 CMSimple Content Management System 2.4 Beta 1 CMSimple Content Management System 2.4 Beta CMSimple Content Management System 2.3 Beta 5 CMSimple Content Management System 2.3 Beta 4 CMSimple Content Management System 2.3 Beta 3 CMSimple Content Management System 2.3 Beta 2 CMSimple Content Management System 2.3 Beta 1 CMSimple Content Management System 2.3 CMSimple Content Management System 2.2 Beta 4 CMSimple Content Management System 2.2 Beta 3 CMSimple Content Management System 2.2 Beta 2 CMSimple Content Management System 2.2 Beta 1 CMSimple Content Management System 2.2 CMSimple Content Management System 2.1 CMSimple Content Management System 2.0 Beta 4 CMSimple Content Management System 2.0 Beta 3 CMSimple Content Management System 2.0 Beta 2 CMSimple Content Management System 2.0 Beta 1 CMSimple Content Management System 1.3 Beta 2 CMSimple Content Management System 1.3 Beta 1 CMSimple Content Management System 1.2 CMSimple Content Management System 1.1 CMSimple Content Management System 1.0 CMSimple Content Management System Beta 2 CMSimple Content Management System Beta 1 |
| Not Vulnerable: | |
Discussion
CMSimple Index.PHP Search Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability affects CMSimple. This issue is due to a failure of the application to properly sanitize user-supplied URI input that will be output in dynamically generated Web pages.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
A cross-site scripting vulnerability affects CMSimple. This issue is due to a failure of the application to properly sanitize user-supplied URI input that will be output in dynamically generated Web pages.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
CMSimple Index.PHP Search Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
CMSimple Index.PHP Search Cross-Site Scripting Vulnerability
Solution:
The vendor has released a fix at http://www.cmsimple.dk/forum/viewtopic.php?t=2470.
Solution:
The vendor has released a fix at http://www.cmsimple.dk/forum/viewtopic.php?t=2470.
References
CMSimple Index.PHP Search Cross-Site Scripting Vulnerability
References:
References:
- CMSimple search variable XSS (Lostmon)
- CMSimple Home Page (CMSimple)
- CMSimple XXS vulnerable (CMSimple)