EasyCMS Multiple Cross-Site Scripting Vulnerabilities
BID:16430
Info
EasyCMS Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 16430 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2006 12:00AM |
| Updated: | Feb 07 2006 08:53PM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
EasyCMS EasyCMS 0 |
| Not Vulnerable: | |
Discussion
EasyCMS Multiple Cross-Site Scripting Vulnerabilities
EasyCMS is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
EasyCMS is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
EasyCMS Multiple Cross-Site Scripting Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
EasyCMS Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has announced that fixes for this issue are pending. Please see the vendor Web site for updated information regarding these vulnerabilities.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has announced that fixes for this issue are pending. Please see the vendor Web site for updated information regarding these vulnerabilities.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EasyCMS Multiple Cross-Site Scripting Vulnerabilities
References:
References: