IDevSpot TextAds Multiple Cross Site Scripting Vulnerabilities
BID:19932
CVE-2006-4747 |Info
IDevSpot TextAds Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 19932 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2006 12:00AM |
| Updated: | Sep 11 2006 07:07PM |
| Credit: | s3rv3r_hack3r is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
IDevSpot TextAds 0 |
| Not Vulnerable: | |
Discussion
IDevSpot TextAds Multiple Cross Site Scripting Vulnerabilities
TextAds is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
TextAds is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
IDevSpot TextAds Multiple Cross Site Scripting Vulnerabilities
An attacker can exploit these vulnerabilities with a web browser.
The following proof-of-concept URIs are available:
An attacker can exploit these vulnerabilities with a web browser.
The following proof-of-concept URIs are available:
Solution / Fix
IDevSpot TextAds Multiple Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
IDevSpot TextAds Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Vendor Homepage (IDevSpot)
- text ads xss attack (s3rv3r_hack3r)