YaPig Script Injection Vulnerability
BID:14670
Info
YaPig Script Injection Vulnerability
| Bugtraq ID: | 14670 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2005 12:00AM |
| Updated: | Aug 26 2005 12:00AM |
| Credit: | Cedric Cochin is credited with the discovery of this vulnerability. |
| Vulnerable: |
YaPiG YaPig 0.95 b YaPiG YaPig 0.95 YaPiG YaPig 0.94 u YaPiG YaPig 0.93 u YaPiG YaPig 0.92 b |
| Not Vulnerable: | |
Discussion
YaPig Script Injection Vulnerability
YaPig is prone to a script injection vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A malicious user may cause arbitrary script code to be executed in the Web browser context of an unsuspecting victim. This may lead to the theft of cookie-based authentication credentials in the context of the victim's browser application.
Further attacks are also possible.
YaPig is prone to a script injection vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A malicious user may cause arbitrary script code to be executed in the Web browser context of an unsuspecting victim. This may lead to the theft of cookie-based authentication credentials in the context of the victim's browser application.
Further attacks are also possible.
Exploit / POC
YaPig Script Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
YaPig Script Injection Vulnerability
Solution:
No exploit is required.
Solution:
No exploit is required.
References
YaPig Script Injection Vulnerability
References:
References:
- Multiple PHP Images Galleries EXIF Metadata XSS Vulnerabilities (Cedric Cochin)
- YaPig Web Site (YaPig)