Roller Multiple Cross-Site Scripting Vulnerabilities
BID:20045
CVE-2006-4856 |Info
Roller Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 20045 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2006 12:00AM |
| Updated: | Sep 16 2006 12:02AM |
| Credit: | Avinash Shenoi is credited with the discovery of this vulnerability. |
| Vulnerable: |
Roller Roller 2.3 |
| Not Vulnerable: |
Roller Roller 2.3.1 |
Discussion
Roller Multiple Cross-Site Scripting Vulnerabilities
Roller is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
An attacker could exploit this vulnerability to have arbitrary script code execute in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
Roller is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
An attacker could exploit this vulnerability to have arbitrary script code execute in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Roller Multiple Cross-Site Scripting Vulnerabilities
An attacker can exploit this issue via a web client.
An attacker can exploit this issue via a web client.
Solution / Fix
Roller Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor is releasing version 2.3.1 to address this issue.
Please see the references for information on how to acquire this fix.
Solution:
The vendor is releasing version 2.3.1 to address this issue.
Please see the references for information on how to acquire this fix.
References
Roller Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Bug Report (David Johsnon)
- Roller Download Page (Roller)
- Vendor Homepage (Roller)
- Roller Weblogger XSS vulnerability ([email protected] )