E107 Website System BBCode HTML Injection Vulnerability
BID:16614
Info
E107 Website System BBCode HTML Injection Vulnerability
| Bugtraq ID: | 16614 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2006 12:00AM |
| Updated: | Feb 14 2006 05:23PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
e107 e107 website system 0.6171 e107 e107 website system 0.617 e107 e107 website system 0.616 e107 e107 website system 0.603 e107 e107 website system 0.555 Beta e107 e107 website system 0.554 e107 e107 website system 0.545 e107 e107 website system 0.7.1 e107 e107 website system 0.7 e107 e107 website system 0.6 15a e107 e107 website system 0.6 15 e107 e107 website system 0.6 14 e107 e107 website system 0.6 13 e107 e107 website system 0.6 12 e107 e107 website system 0.6 11 e107 e107 website system 0.6 10 e107 e107 website system 0.6175 |
| Not Vulnerable: |
e107 e107 website system 0.7.2 |
Discussion
E107 Website System BBCode HTML Injection Vulnerability
The e107 content management system (CMS) is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
The e107 content management system (CMS) is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
E107 Website System BBCode HTML Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
E107 Website System BBCode HTML Injection Vulnerability
Solution:
The vendor has released version 0.7.2 of e107 Website System to address this issue.
e107 e107 website system 0.6175
e107 e107 website system 0.545
e107 e107 website system 0.554
e107 e107 website system 0.555 Beta
e107 e107 website system 0.6 13
e107 e107 website system 0.6 10
e107 e107 website system 0.6 14
e107 e107 website system 0.6 12
e107 e107 website system 0.6 15a
e107 e107 website system 0.6 15
e107 e107 website system 0.6 11
e107 e107 website system 0.603
e107 e107 website system 0.616
e107 e107 website system 0.617
e107 e107 website system 0.6171
e107 e107 website system 0.7
e107 e107 website system 0.7.1
Solution:
The vendor has released version 0.7.2 of e107 Website System to address this issue.
e107 e107 website system 0.6175
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.545
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.554
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.555 Beta
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6 13
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6 10
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6 14
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6 12
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6 15a
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6 15
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6 11
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.603
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.616
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.617
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.6171
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.7
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
e107 e107 website system 0.7.1
-
e107.org e107_v0.7.2_full.tar.gz
http://prdownloads.sourceforge.net/e107/e107_v0.7.2_full.tar.gz?downlo ad
References
E107 Website System BBCode HTML Injection Vulnerability
References:
References:
- e107 website system Homepage (e107.org)
- Security and Bug Fixes Release 0.7.2 (e107.org)