CPAINT TYPE.PHP Cross-Site Scripting Vulnerability
BID:16559
Info
CPAINT TYPE.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 16559 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2006 12:00AM |
| Updated: | Dec 13 2006 04:48PM |
| Credit: | Discovered by James Bercegay. |
| Vulnerable: |
CPAINT CPAINT 2.0.2 CPAINT CPAINT 1.3 -SP CPAINT CPAINT 1.3 |
| Not Vulnerable: |
CPAINT CPAINT 2.0.3 |
Discussion
CPAINT TYPE.PHP Cross-Site Scripting Vulnerability
CPAINT is prone to a cross-site scripting vulnerability.
This issue affects the 'type.php' script and may facilitate the theft of cookie-based authentication credentials as well as other attacks.
CPAINT 2.0.2 and prior versions are affected.
CPAINT is prone to a cross-site scripting vulnerability.
This issue affects the 'type.php' script and may facilitate the theft of cookie-based authentication credentials as well as other attacks.
CPAINT 2.0.2 and prior versions are affected.
Exploit / POC
CPAINT TYPE.PHP Cross-Site Scripting Vulnerability
An exploit is not required.
The following proof of concept is available:
http://www.example.com/examples/type/type.php?cpaint_response_type=%3Ciframe%20src=http://www.gulftech.org/%3E
An exploit is not required.
The following proof of concept is available:
http://www.example.com/examples/type/type.php?cpaint_response_type=%3Ciframe%20src=http://www.gulftech.org/%3E
Solution / Fix
CPAINT TYPE.PHP Cross-Site Scripting Vulnerability
Solution:
The vendor has released CPAINT 2.0.3 to address this issue.
CPAINT CPAINT 1.3 -SP
CPAINT CPAINT 1.3
CPAINT CPAINT 2.0.2
Solution:
The vendor has released CPAINT 2.0.3 to address this issue.
CPAINT CPAINT 1.3 -SP
-
CPAINT cpaint-2.0.3.tar.gz
http://prdownloads.sourceforge.net/cpaint/cpaint-2.0.3.tar.gz?download
CPAINT CPAINT 1.3
-
CPAINT cpaint-2.0.3.tar.gz
http://prdownloads.sourceforge.net/cpaint/cpaint-2.0.3.tar.gz?download
CPAINT CPAINT 2.0.2
-
CPAINT cpaint-2.0.3.tar.gz
http://prdownloads.sourceforge.net/cpaint/cpaint-2.0.3.tar.gz?download
References
CPAINT TYPE.PHP Cross-Site Scripting Vulnerability
References:
References:
- CPAINT Homepage (CPAINT)
- CPAINT security hole found and fixed! (CPAINT)
- CPAINT AJAX Library Cross Site Scripting (GulfTech Security Research
)