TDiary Conf Parameter Cross-Site Scripting Vulnerabilities
BID:21321
Info
TDiary Conf Parameter Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 21321 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2006 12:00AM |
| Updated: | Nov 28 2006 11:10PM |
| Credit: | Fukumori and the vendor reported this vulnerability. |
| Vulnerable: |
tDiary tDiary 2.0.2 tDiary tDiary 2.1.4.20061115 |
| Not Vulnerable: |
tDiary tDiary 2.0.3 tDiary tDiary 2.1.4.20061126 |
Discussion
TDiary Conf Parameter Cross-Site Scripting Vulnerabilities
tDiary is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
tDiary versions 2.1.4.20061115 and prior are vulnerable to these issues.
tDiary is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
tDiary versions 2.1.4.20061115 and prior are vulnerable to these issues.
Exploit / POC
TDiary Conf Parameter Cross-Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
TDiary Conf Parameter Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released versions 2.0.3 and 2.1.4.20061126 to address these issues. Please see the reference section for further information.
tDiary tDiary 2.1.4.20061115
tDiary tDiary 2.0.2
Solution:
The vendor has released versions 2.0.3 and 2.1.4.20061126 to address these issues. Please see the reference section for further information.
tDiary tDiary 2.1.4.20061115
-
tDiary tdiary-contrib-20060415.tar.gz
http://downloads.sourceforge.net/tdiary/tdiary-contrib-20060415.tar.gz
tDiary tDiary 2.0.2
-
tDiary tdiary-full-2.0.3.tar.gz
http://downloads.sourceforge.net/tdiary/tdiary-full-2.0.3.tar.gz
References
TDiary Conf Parameter Cross-Site Scripting Vulnerabilities
References:
References:
- JP Vendor Status Notes (JP Vendor)
- Vendor Homepage (tDiary)