Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BID:18653
Info
Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 18653 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2006 12:00AM |
| Updated: | Jun 26 2006 07:25PM |
| Credit: | The vendor credits Secure Systems Lab with the discovery of this vulnerability. |
| Vulnerable: |
Qdig Qdig 1.2.9 .2 |
| Not Vulnerable: |
Qdig Qdig 1.2.9 .3 |
Discussion
Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
Qdig is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.2.9.2; earlier versions may also be vulnerable.
Qdig is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.2.9.2; earlier versions may also be vulnerable.
Exploit / POC
Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
This issue can be triggered by tricking a victim user into following a malicious URI.
This issue can be triggered by tricking a victim user into following a malicious URI.
Solution / Fix
Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released version 1.2.9.3 to address this issue.
Qdig Qdig 1.2.9 .2
Solution:
The vendor has released version 1.2.9.3 to address this issue.
Qdig Qdig 1.2.9 .2
-
Qdig qdig.tar.gz
http://qdig.sourceforge.net/files/qdig.tar.gz
References
Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- New Stable Release: Qdig 1.2.9.3 (Qdig)
- Qdig Homepage (Qdig)