MAXdev MD-Pro Cross-Site Scripting Vulnerability
BID:14742
Info
MAXdev MD-Pro Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14742 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2005 12:00AM |
| Updated: | Sep 05 2005 12:00AM |
| Credit: | Discovered by "D'Amato Daniele" <[email protected]>. |
| Vulnerable: |
MAXdev MD-Pro 1.0.72 |
| Not Vulnerable: |
MAXdev MD-Pro 1.0.73 |
Discussion
MAXdev MD-Pro Cross-Site Scripting Vulnerability
Cross-site scripting vulnerabilities reportedly affect MD-Pro The vulnerabilities exist in the "wl-search.php" and "dl-search.php" scripts and are due to input validation errors. Successful exploitation may allow for attacks against other users of the application or others hosted on the same domain. Session hijacking, content spoofing and other attacks may be possible.
Cross-site scripting vulnerabilities reportedly affect MD-Pro The vulnerabilities exist in the "wl-search.php" and "dl-search.php" scripts and are due to input validation errors. Successful exploitation may allow for attacks against other users of the application or others hosted on the same domain. Session hijacking, content spoofing and other attacks may be possible.
Exploit / POC
MAXdev MD-Pro Cross-Site Scripting Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
MAXdev MD-Pro Cross-Site Scripting Vulnerability
Solution:
The vendor has released upgrade version 1.0.73:
http://www.maxdev.com/Downloads-index-req-viewdownload-cid-3.phtml
Solution:
The vendor has released upgrade version 1.0.73:
http://www.maxdev.com/Downloads-index-req-viewdownload-cid-3.phtml