Sawmill Unspecified Cross-Site Scripting Vulnerability
BID:14789
Info
Sawmill Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14789 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2005 12:00AM |
| Updated: | Sep 09 2005 12:00AM |
| Credit: | Jan Blunck <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Sawmill Sawmill 7.1.13 |
| Not Vulnerable: |
Sawmill Sawmill 7.1.14 |
Discussion
Sawmill Unspecified Cross-Site Scripting Vulnerability
Sawmill is prone to an unspecified cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Sawmill is prone to an unspecified cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Sawmill Unspecified Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Sawmill Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released version 7.1.14 to address this issue.
Sawmill Sawmill 7.1.13
Solution:
The vendor has released version 7.1.14 to address this issue.
Sawmill Sawmill 7.1.13
-
Sawmill sawmill7_download.pl
http://www.sawmill.net/cgi-bin/sawmill7_download.pl
References
Sawmill Unspecified Cross-Site Scripting Vulnerability
References:
References:
- Sawmill Homepage (Sawmill)
- Sawmill Version History Version 7 (Sawmill)