SpearTek Search Module Cross-Site Scripting Vulnerability
BID:16018
Info
SpearTek Search Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 16018 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2005 12:00AM |
| Updated: | Nov 08 2006 10:31PM |
| Credit: | rakstija r0t3d3Vil is credited with the discovery of this vulnerability. |
| Vulnerable: |
SpearTek SpearTek 6.0 |
| Not Vulnerable: |
SpearTek SpearTek 7.0 |
Discussion
SpearTek Search Module Cross-Site Scripting Vulnerability
SpearTek is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 6.0; other versions may also be vulnerable.
SpearTek is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 6.0; other versions may also be vulnerable.
Exploit / POC
SpearTek Search Module Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
SpearTek Search Module Cross-Site Scripting Vulnerability
Solution:
The vendor has released version 7.0.0 to address this issue. Please see the referenced site for information on how to obtain and apply this fix.
Solution:
The vendor has released version 7.0.0 to address this issue. Please see the referenced site for information on how to obtain and apply this fix.
References
SpearTek Search Module Cross-Site Scripting Vulnerability
References:
References:
- SpearTek Homepage (SpearTek)
- Speartek XSS vuln. (rakstija r0t3d3Vil)