Zope HTTP Get Request HTML Injection Vulnerability
BID:23084
Info
Zope HTTP Get Request HTML Injection Vulnerability
| Bugtraq ID: | 23084 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0240 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2007 12:00AM |
| Updated: | May 16 2007 10:28PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Zope Zope 2.10.2 Zope Zope 2.10.1 Zope Zope 2.9.3 Zope Zope 2.9.2 Zope Zope 2.9.1 Zope Zope 2.9 Zope Zope 2.8.8 Zope Zope 2.8.7 Zope Zope 2.8.6 Zope Zope 2.8.5 Zope Zope 2.8.4 Zope Zope 2.8.3 Zope Zope 2.8.2 Zope Zope 2.8.1 SuSE SUSE Linux Enterprise Server 10 SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10 SuSE Linux 9.3 x86-64 SuSE Linux 9.3 x86 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 10.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Zope HTTP Get Request HTML Injection Vulnerability
Zope is prone to an HTML-injection scripting vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Zope is prone to an HTML-injection scripting vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
Zope HTTP Get Request HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Zope HTTP Get Request HTML Injection Vulnerability
Solution:
The vendor has released a hotfix to address this issue; please see the references for more information.
Zope Zope 2.10.1
Zope Zope 2.10.2
Zope Zope 2.8.1
Zope Zope 2.8.2
Zope Zope 2.8.3
Zope Zope 2.8.4
Zope Zope 2.8.5
Zope Zope 2.8.6
Zope Zope 2.8.7
Zope Zope 2.8.8
Zope Zope 2.9
Zope Zope 2.9.1
Zope Zope 2.9.2
Zope Zope 2.9.3
Solution:
The vendor has released a hotfix to address this issue; please see the references for more information.
Zope Zope 2.10.1
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.10.2
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.1
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.2
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.3
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.4
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.5
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.6
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.7
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.8.8
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.9
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.9.1
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.9.2
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
Zope Zope 2.9.3
-
Zope Hotfix_20070320.tgz
http://www.zope.org/Products/Zope/Hotfix-2007-03-20/Hotfix-20070320/Ho tfix_20070320.tgz
References
Zope HTTP Get Request HTML Injection Vulnerability
References:
References:
- Zope Home Page (Zope)
- Zope Hotfix 2007-03-20 (Zope)