SiteScape Forum Multiple Unspecified Cross-Site Scripting Vulnerabilities
BID:24893
Info
SiteScape Forum Multiple Unspecified Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 24893 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3807 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Discovered by Marc Ruef. |
| Vulnerable: |
SiteScape forum 7.2 |
| Not Vulnerable: | |
Discussion
SiteScape Forum Multiple Unspecified Cross-Site Scripting Vulnerabilities
SiteScape Forum is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Reports indicate that these issues affect versions prior to SiteScape Forum 7.3.
SiteScape Forum is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Reports indicate that these issues affect versions prior to SiteScape Forum 7.3.
Exploit / POC
SiteScape Forum Multiple Unspecified Cross-Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
SiteScape Forum Multiple Unspecified Cross-Site Scripting Vulnerabilities
Solution:
Reports indicate that the vendor has released Forum 7.3 to address these issues, but Symantec was unable to verify this information. Please contact the vendor for more information.
Solution:
Reports indicate that the vendor has released Forum 7.3 to address these issues, but Symantec was unable to verify this information. Please contact the vendor for more information.
References
SiteScape Forum Multiple Unspecified Cross-Site Scripting Vulnerabilities
References:
References:
- Home Page (SiteScape)
- [scip_Advisory 3159] SiteScape forum prior 7.3 Cross Site Scripting (Marc Ruef
)