XiTi Tracking Script Xiti.JS Cross-Site Scripting Vulnerability
BID:18710
CVE-2006-2795 |Info
XiTi Tracking Script Xiti.JS Cross-Site Scripting Vulnerability
| Bugtraq ID: | 18710 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2006 12:00AM |
| Updated: | Jun 29 2006 04:24PM |
| Credit: | Yannick Daffaud is credited with the discovery of this vulnerability. |
| Vulnerable: |
XiTi XiTi 7 RC 0 XiTi XiTi 6 |
| Not Vulnerable: | |
Discussion
XiTi Tracking Script Xiti.JS Cross-Site Scripting Vulnerability
XiTi Tracking Script is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
XiTi Tracking Script is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
XiTi Tracking Script Xiti.JS Cross-Site Scripting Vulnerability
The issue can be exploited through a web client.
The issue can be exploited through a web client.
Solution / Fix
XiTi Tracking Script Xiti.JS Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].