PHProxy Index.Inc.PHP HTML Injection Vulnerability
BID:22255
Info
PHProxy Index.Inc.PHP HTML Injection Vulnerability
| Bugtraq ID: | 22255 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0553 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2007 12:00AM |
| Updated: | May 12 2015 07:35PM |
| Credit: | Ryan from http://proxy.de is credited with discovery of this vulnerability. |
| Vulnerable: |
PHProxy PHProxy 0.4 PHProxy PHProxy 0.3 PHProxy PHProxy 0.2 PHProxy PHProxy 0.1 PHProxy PHProxy 0.5.0 beta |
| Not Vulnerable: |
PHProxy PHProxy 0.5.0 beta 2 |
Discussion
PHProxy Index.Inc.PHP HTML Injection Vulnerability
PHProxy is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to 0.5 beta 2 are vulnerable to this issue.
PHProxy is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to 0.5 beta 2 are vulnerable to this issue.
Exploit / POC
PHProxy Index.Inc.PHP HTML Injection Vulnerability
An attacker can exploit this issue through a web client.
An attacker can exploit this issue through a web client.
Solution / Fix
PHProxy Index.Inc.PHP HTML Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
PHProxy Index.Inc.PHP HTML Injection Vulnerability
References:
References:
- PHProxy 0.5 Beta 2 Release Notes (PHProxy)
- PHProxy Homepage (PHProxy)