Allinta CMS Multiple Cross-Site Scripting Vulnerabilities
BID:15935
Info
Allinta CMS Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 15935 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 19 2005 12:00AM |
| Credit: | Discovered by rakstija r0t3d3Vil. |
| Vulnerable: |
Allinta allinta CMS 2.3.2 |
| Not Vulnerable: |
Allinta allinta CMS 2.3.3 |
Discussion
Allinta CMS Multiple Cross-Site Scripting Vulnerabilities
Allinta CMS is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Allinta versions 2.3.2 and earlier are reportedly affected by this vulnerability.
Allinta CMS is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Allinta versions 2.3.2 and earlier are reportedly affected by this vulnerability.
Exploit / POC
Allinta CMS Multiple Cross-Site Scripting Vulnerabilities
No exploit is required.
The following examples were provided:
http://example.com/faq.asp?s=[XSS]&roottopicID=&sa=1&submit=Search
http://example.com/search.asp?searchQuery=[XSS]&go=Search&submitted=true
No exploit is required.
The following examples were provided:
http://example.com/faq.asp?s=[XSS]&roottopicID=&sa=1&submit=Search
http://example.com/search.asp?searchQuery=[XSS]&go=Search&submitted=true
Solution / Fix
Allinta CMS Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has addressed this issue in version 2.3.3. Affected users should contact the vendor to obtain fixes.
Solution:
The vendor has addressed this issue in version 2.3.3. Affected users should contact the vendor to obtain fixes.
References
Allinta CMS Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Allinta 2.3.x XSS vuln (rakstija r0t3d3Vil)
- Allinta CMS Changelog (Allinta)
- Allinta CMS Homepage (Allinta)