Joomla! Letterman Subscriber Module Mod_Lettermansubscribe.PHP Cross-Site Scripting Vulnerability
BID:24479
Info
Joomla! Letterman Subscriber Module Mod_Lettermansubscribe.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 24479 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3249 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Edi Strosar of TeamIntell discovered this issue. |
| Vulnerable: |
Joomla Letterman Subscriber Module 1.2.4-RC1 |
| Not Vulnerable: |
Joomla Letterman Subscriber Module 1.2.5 |
Discussion
Joomla! Letterman Subscriber Module Mod_Lettermansubscribe.PHP Cross-Site Scripting Vulnerability
The Joomla! Letterman Subscriber module is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Joomla! Letterman Subscriber 1.2.4-RC1 is vulnerable; other versions may also be affected.
The Joomla! Letterman Subscriber module is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Joomla! Letterman Subscriber 1.2.4-RC1 is vulnerable; other versions may also be affected.
Exploit / POC
Joomla! Letterman Subscriber Module Mod_Lettermansubscribe.PHP Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Sample exploit code has been provided:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Sample exploit code has been provided:
Solution / Fix
Joomla! Letterman Subscriber Module Mod_Lettermansubscribe.PHP Cross-Site Scripting Vulnerability
Solution:
The vendor has released version 1.2.5 to address this issue; please see the reference section for details.
Joomla Letterman Subscriber Module 1.2.4-RC1
Solution:
The vendor has released version 1.2.5 to address this issue; please see the reference section for details.
Joomla Letterman Subscriber Module 1.2.4-RC1
-
Joomla mod_letterman_1_2_5.zip
http://joomlacode.org/gf/download/frsrelease/4853/11893/mod_letterman_ 1_2_5.zip
References
Joomla! Letterman Subscriber Module Mod_Lettermansubscribe.PHP Cross-Site Scripting Vulnerability
References:
References:
- Letterman Subscribe for Joomla! Web Site (Letterman Subscribe)