OWASP WebScarab Cross-Site Scripting Vulnerability
BID:19063
CVE-2006-3841 |Info
OWASP WebScarab Cross-Site Scripting Vulnerability
| Bugtraq ID: | 19063 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3841 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2006 12:00AM |
| Updated: | May 07 2007 04:59PM |
| Credit: | Moritz Naumann IT Consulting & Services is credited with the discovery of this vulnerability. |
| Vulnerable: |
OWASP WebScarab 2006.7.18 1904 OWASP WebScarab 2006.6.21 0003 |
| Not Vulnerable: |
OWASP WebScarab 2007.5.4 1631 |
Discussion
OWASP WebScarab Cross-Site Scripting Vulnerability
The OWASP WebScarab framework is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The OWASP WebScarab framework is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
OWASP WebScarab Cross-Site Scripting Vulnerability
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
OWASP WebScarab Cross-Site Scripting Vulnerability
Solution:
Version 20060718-1904 did not adequately address the vulnerability. The vendor has released a new version, 20070504-1631, that does fix the vulnerability.
OWASP WebScarab 2006.6.21 0003
OWASP WebScarab 2006.7.18 1904
Solution:
Version 20060718-1904 did not adequately address the vulnerability. The vendor has released a new version, 20070504-1631, that does fix the vulnerability.
OWASP WebScarab 2006.6.21 0003
-
OWASP WebScarab 20070504-1631
https://sourceforge.net/project/showfiles.php?group_id=64424&package_i d=61823
OWASP WebScarab 2006.7.18 1904
-
OWASP WebScarab 20070504-1631
https://sourceforge.net/project/showfiles.php?group_id=64424&package_i d=61823
References
OWASP WebScarab Cross-Site Scripting Vulnerability
References:
References:
- Vendor Homepage (OWASP)
- WebScarab Homepage (OWASP)
- Re: WebScarab <= 20060621-0003 cross site scripting (Rogan Dawes
)