EPiX Search Module Cross-Site Scripting Vulnerability
BID:15944
Info
EPiX Search Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15944 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Jan 05 2007 10:46PM |
| Credit: | Discovered by rakstija r0t3d3Vil. |
| Vulnerable: |
EPiX EPiX 3.1.2 |
| Not Vulnerable: |
EPiX EPiX 3.1.3 |
Discussion
EPiX Search Module Cross-Site Scripting Vulnerability
EPiX is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
EPiX is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
EPiX Search Module Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
EPiX Search Module Cross-Site Scripting Vulnerability
Solution:
The vendor has released an update to address this issue. Please contact the vendor for information on how to obtain and apply this update.
Solution:
The vendor has released an update to address this issue. Please contact the vendor for information on how to obtain and apply this update.
References
EPiX Search Module Cross-Site Scripting Vulnerability
References:
References:
- EPiX 3.1.3 Release Notes (EPiX)
- EPiX Home Page (EPiX)
- EPiX? Search query XSS vuln. (rakstija r0t3d3Vil)