AckerTodo Index.PHP Cross-Site Scripting Vulnerability
BID:19894
CVE-2006-4668 |Info
AckerTodo Index.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 19894 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2006 12:00AM |
| Updated: | Sep 27 2006 10:56PM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Rob Hensley ackerTodo 4.0 |
| Not Vulnerable: | |
Discussion
AckerTodo Index.PHP Cross-Site Scripting Vulnerability
AckerTodo is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue would allow an attacker to steal cookie-based credentials and to launch other attacks.
Version 4.0 is vulnerable; other versions may also be affected.
AckerTodo is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue would allow an attacker to steal cookie-based credentials and to launch other attacks.
Version 4.0 is vulnerable; other versions may also be affected.
Exploit / POC
AckerTodo Index.PHP Cross-Site Scripting Vulnerability
An attacker can exploit this vulnerability using a web client.
The following proof of concept is available:
An attacker can exploit this vulnerability using a web client.
The following proof of concept is available:
Solution / Fix
AckerTodo Index.PHP Cross-Site Scripting Vulnerability
Solution:
The vendor has address this issue in the current CVS and will releasing an updated version of this application in the near future. Please see the references for more information on how to obtain and apply this update.
Solution:
The vendor has address this issue in the current CVS and will releasing an updated version of this application in the near future. Please see the references for more information on how to obtain and apply this update.
References
AckerTodo Index.PHP Cross-Site Scripting Vulnerability
References:
References: