ATutor Multiple Cross-Site Scripting Vulnerabilities
BID:18857
CVE-2006-3484 |Info
ATutor Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 18857 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2006 12:00AM |
| Updated: | Jul 06 2006 11:44PM |
| Credit: | Security News is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
ATutor ATutor 1.5.1 pl2 ATutor ATutor 1.5.1 pl1 ATutor ATutor 1.5.1 ATutor ATutor 1.5.3 RC2 |
| Not Vulnerable: |
ATutor ATutor 1.5.3 |
Discussion
ATutor Multiple Cross-Site Scripting Vulnerabilities
ATutor is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage any of these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 1.5.1 and 1.5.3 RC2 are vulnerable; other versions may also be affected.
ATutor is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage any of these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 1.5.1 and 1.5.3 RC2 are vulnerable; other versions may also be affected.
Exploit / POC
ATutor Multiple Cross-Site Scripting Vulnerabilities
These issues can be exploited through a web client.
The following proof-of-concept URIs are available:
These issues can be exploited through a web client.
The following proof-of-concept URIs are available:
Solution / Fix
ATutor Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released version 1.5.3 to address these issues; please see the reference section for details.
ATutor ATutor 1.5.3 RC2
ATutor ATutor 1.5.1 pl2
ATutor ATutor 1.5.1 pl1
ATutor ATutor 1.5.1
Solution:
The vendor has released version 1.5.3 to address these issues; please see the reference section for details.
ATutor ATutor 1.5.3 RC2
-
ATutor ATutor-1.5.3.tar.gz
http://prdownloads.sourceforge.net/atutor/ATutor-1.5.3.tar.gz
ATutor ATutor 1.5.1 pl2
-
ATutor ATutor-1.5.3.tar.gz
http://prdownloads.sourceforge.net/atutor/ATutor-1.5.3.tar.gz
ATutor ATutor 1.5.1 pl1
-
ATutor ATutor-1.5.3.tar.gz
http://prdownloads.sourceforge.net/atutor/ATutor-1.5.3.tar.gz
ATutor ATutor 1.5.1
-
ATutor ATutor-1.5.3.tar.gz
http://prdownloads.sourceforge.net/atutor/ATutor-1.5.3.tar.gz
References
ATutor Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- ATutor Bug Reports (ATutor)
- ATutor Homepage (ATutor)