ADOdb Multiple Cross-Site Scripting Vulnerabilities
BID:16720
Info
ADOdb Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 16720 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0806 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2006 12:00AM |
| Updated: | Apr 17 2006 08:41PM |
| Credit: | GulfTech Security Research <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 ADOdb ADOdb 4.71 ADOdb ADOdb 4.70 ADOdb ADOdb 4.68 ADOdb ADOdb 4.66 |
| Not Vulnerable: | |
Discussion
ADOdb Multiple Cross-Site Scripting Vulnerabilities
ADOdb is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may help the attacker steal cookie-based authentication credentials and launch other attacks.
ADOdb versions 4.71 and prior are vulnerable.
ADOdb is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may help the attacker steal cookie-based authentication credentials and launch other attacks.
ADOdb versions 4.71 and prior are vulnerable.
Exploit / POC
ADOdb Multiple Cross-Site Scripting Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
ADOdb Multiple Cross-Site Scripting Vulnerabilities
Solution:
Debian Linux has released security advisories DSA 1029-1 and DSA 1030-1 to address this issue. Please see the referenced vendor advisories for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Debian Linux has released security advisories DSA 1029-1 and DSA 1030-1 to address this issue. Please see the referenced vendor advisories for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
ADOdb Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- ADOdb Lite Homepage (ADOdb)
- ADOdb Library Cross Site Scripting (GulfTech Security Research
)