XOOPS Multiple HTML Injection Vulnerabilities
BID:15195
Info
XOOPS Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 15195 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2005 12:00AM |
| Updated: | Oct 25 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
xoopscube xoopscube 2.0.13 JP xoopscube xoopscube 2.0.12 JP Xoops Xoops 2.2.3 RC1 Xoops Xoops 2.2.1 Xoops Xoops 2.0.13 .1 Xoops Xoops 2.0.12 a Xoops Xoops 2.0.12 Xoops Xoops 2.0.11 Xoops Xoops 2.0.10 Xoops Xoops 2.0.9 .3 Xoops Xoops 2.0.9 .2 Xoops Xoops 2.0.5 .2 Xoops Xoops 2.0.5 .1 Xoops Xoops 2.0.5 Xoops Xoops 2.0.3 Xoops Xoops 2.0.2 Xoops Xoops 2.0.1 Xoops Xoops 2.0 Xoops Xoops 1.3.10 Xoops Xoops 1.3.9 Xoops Xoops 1.3.8 Xoops Xoops 1.3.7 Xoops Xoops 1.3.6 Xoops Xoops 1.3.5 Xoops Xoops 1.0 RC1 Xoops Xoops 1.0 RC3.0.5 Xoops Xoops 1.0 RC3 |
| Not Vulnerable: |
xoopscube xoopscube 2.0.13 a JP Xoops Xoops 2.0.13 .2 |
Discussion
XOOPS Multiple HTML Injection Vulnerabilities
XOOPS is prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
XOOPS is prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
XOOPS Multiple HTML Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
XOOPS Multiple HTML Injection Vulnerabilities
Solution:
The vendor has released version 2.0.13.2 to resolve this issue. Please see the references section for further information.
xoopscube has released version 2.0.13a jp to resolve this issue. Please see the referenced section for further information.
Xoops Xoops 2.0
Xoops Xoops 2.0.1
Xoops Xoops 2.0.10
Xoops Xoops 2.0.11
Xoops Xoops 2.0.12
xoopscube xoopscube 2.0.12 JP
Xoops Xoops 2.0.12 a
Xoops Xoops 2.0.13 .1
xoopscube xoopscube 2.0.13 JP
Xoops Xoops 2.0.2
Xoops Xoops 2.0.3
Xoops Xoops 2.0.5
Xoops Xoops 2.0.5 .1
Xoops Xoops 2.0.5 .2
Xoops Xoops 2.0.9 .3
Xoops Xoops 2.0.9 .2
Solution:
The vendor has released version 2.0.13.2 to resolve this issue. Please see the references section for further information.
xoopscube has released version 2.0.13a jp to resolve this issue. Please see the referenced section for further information.
Xoops Xoops 2.0
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.1
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.10
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.11
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.12
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
xoopscube xoopscube 2.0.12 JP
-
xoopscube xoops-2.0.13a-JP.tar.gz
http://prdownloads.sourceforge.jp/xoops/17125/xoops-2.0.13a-JP.tar.gz
Xoops Xoops 2.0.12 a
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.13 .1
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
xoopscube xoopscube 2.0.13 JP
-
xoopscube xoops-2.0.13a-JP.tar.gz
http://prdownloads.sourceforge.jp/xoops/17125/xoops-2.0.13a-JP.tar.gz
Xoops Xoops 2.0.2
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.3
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.5
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.5 .1
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.5 .2
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.9 .3
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
Xoops Xoops 2.0.9 .2
-
Xoops Xoops 2.0.13.2
http://www.xoops.org/modules/core/visit.php?cid=4&lid=119&type=2
References
XOOPS Multiple HTML Injection Vulnerabilities
References:
References: