Mambo LaiThai Unspecified Cross-Site Scripting Vulnerability
BID:20458
CVE-2006-7093 |Info
Mambo LaiThai Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 20458 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2006 12:00AM |
| Updated: | Oct 12 2006 06:49PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
Mambo LaiThai 4.5.4 Security Patch 2 |
| Not Vulnerable: | |
Discussion
Mambo LaiThai Unspecified Cross-Site Scripting Vulnerability
Mambo LaiThai is prone to an unspecified cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 4.5.4 security patch 2 is confirmed affected; other versions may be vulnerable as well.
Mambo LaiThai is prone to an unspecified cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 4.5.4 security patch 2 is confirmed affected; other versions may be vulnerable as well.
Exploit / POC
Mambo LaiThai Unspecified Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Mambo LaiThai Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released a security patch that addresses this issue. Please see the vendor advisory for more information.
Mambo LaiThai 4.5.4 Security Patch 2
Solution:
The vendor has released a security patch that addresses this issue. Please see the vendor advisory for more information.
Mambo LaiThai 4.5.4 Security Patch 2
-
Mambo Mambo LaiThai 4.5.x Security Patch3
http://mamboxchange.com/forum/forum.php?forum_id=7767
References
Mambo LaiThai Unspecified Cross-Site Scripting Vulnerability
References:
References:
- Mambo LaiThai 4.5.x Security Patch3 (Mambo LaiThai)
- Mambo LaiThai Homepage (Mambo LaiThai)