Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
BID:24480
Info
Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 24480 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3101 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2007 12:00AM |
| Updated: | Jun 15 2007 04:39AM |
| Credit: | This vulnerability was reported to iDefense by Rajat Swarup of VeriSign Global Security Consulting. |
| Vulnerable: |
Apache MyFaces Tomahawk 1.1.5 |
| Not Vulnerable: |
Apache MyFaces Tomahawk 1.1.6 |
Discussion
Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
Apache Tomahawk MyFaces JSF Framework is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this vulnerability may allow an attacker to launch cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.
Apache Tomahawk MyFaces JSF Framework is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this vulnerability may allow an attacker to launch cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept URI is available:
http:/;www.example.com/some_app.jsf?autoscroll=[javascript]
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept URI is available:
http:/;www.example.com/some_app.jsf?autoscroll=[javascript]
Solution / Fix
Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
Solution:
The vendor has released version 1.1.6 to address this issue; please see the reference section for details.
Apache MyFaces Tomahawk 1.1.5
Solution:
The vendor has released version 1.1.6 to address this issue; please see the reference section for details.
Apache MyFaces Tomahawk 1.1.5
-
Apache tomahawk-1.1.6-bin.tar.gz
http://www.apache.org/dyn/closer.cgi/myfaces/binaries/tomahawk-1.1.6-b in.tar.gz
References
Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability
References:
References:
- Apache Java Server Faces Web Site (Apache Java Server Faces)
- Release Notes - MyFaces Tomahawk - Version 1.1.6 - Text format (Apache MyFaces Tomahawk)
- iDefense Security Advisory 06.14.07: Apache MyFaces Tomahawk JSF Framework Cross (iDefense Labs
)