AutoRank Multiple Cross-Site Scripting Vulnerabilities
BID:18796
CVE-2006-3377 |Info
AutoRank Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 18796 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2006 12:00AM |
| Updated: | Jul 05 2006 05:14PM |
| Credit: | [email protected] is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
JMB Software Auto Rank PRO 5.01 JMB Software Auto Rank PHP 3.02 |
| Not Vulnerable: | |
Discussion
AutoRank Multiple Cross-Site Scripting Vulnerabilities
AutoRank is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before displaying it to users of the application.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
AutoRank PHP 3.02 and AutoRank PRO 5.01, as well as prior versions of each of these applications, are affected.
AutoRank is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input before displaying it to users of the application.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
AutoRank PHP 3.02 and AutoRank PRO 5.01, as well as prior versions of each of these applications, are affected.
Exploit / POC
AutoRank Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues through a web client.
Attackers can exploit these issues through a web client.
Solution / Fix
AutoRank Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
AutoRank Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- [MajorSecurity #19] AutoRank <= 5.01 - Multiple XSS and cookie ([email protected])
- Auto Rank PHP Home Page (JMB Software)
- Auto Rank Pro Home Page (JMB Software )