WikiNi Waka.PHP Multiple HTML-Injection Vulnerabilities
BID:20688
Info
WikiNi Waka.PHP Multiple HTML-Injection Vulnerabilities
| Bugtraq ID: | 20688 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2006 12:00AM |
| Updated: | Oct 26 2006 03:43PM |
| Credit: | Raphael Huck is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
WikiNi WikiNi 0.4.3 WikiNi WikiNi 0.4.2 |
| Not Vulnerable: |
WikiNi WikiNi 0.4.4 |
Discussion
WikiNi Waka.PHP Multiple HTML-Injection Vulnerabilities
WikiNi is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data before using it in dynamically generated content.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials, control how the site is rendered, and launch other attacks.
WikiNi versions prior to 0.4.4 are vulnerable.
WikiNi is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data before using it in dynamically generated content.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials, control how the site is rendered, and launch other attacks.
WikiNi versions prior to 0.4.4 are vulnerable.
Exploit / POC
WikiNi Waka.PHP Multiple HTML-Injection Vulnerabilities
An attacker can exploit this issue with a web client.
Sample exploit code has been provided:
An attacker can exploit this issue with a web client.
Sample exploit code has been provided:
Solution / Fix
WikiNi Waka.PHP Multiple HTML-Injection Vulnerabilities
Solution:
The vendor has addressed these issues in version 0.4.4; please see the referenced advisories for more information.
WikiNi WikiNi 0.4.2
WikiNi WikiNi 0.4.3
Solution:
The vendor has addressed these issues in version 0.4.4; please see the referenced advisories for more information.
WikiNi WikiNi 0.4.2
-
WikiNi wikini-0.4.4.tar.gz
http://www.wikini.net/download/wikini-0.4.4.tar.gz
WikiNi WikiNi 0.4.3
-
WikiNi wikini-0.4.4.tar.gz
http://www.wikini.net/download/wikini-0.4.4.tar.gz
References
WikiNi Waka.PHP Multiple HTML-Injection Vulnerabilities
References:
References: