JBlog Multiple Input Validation Vulnerabilities
BID:24991
Info
JBlog Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 24991 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3974 CVE-2007-3973 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | s4mi is credited with the discovery of these vulnerabilities. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
JBlog Multiple Input Validation Vulnerabilities
JBlog is prone to multiple input-validation vulnerabilities, including cross-site scripting and HTML-injection issues, because the application fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, execute arbitrary script code in the context of the webserver process, control how the site is rendered to the user, compromise the application, obtain sensitive information, and access or modify data.
JBlog 1.0 is vulnerable to these issues.
JBlog is prone to multiple input-validation vulnerabilities, including cross-site scripting and HTML-injection issues, because the application fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, execute arbitrary script code in the context of the webserver process, control how the site is rendered to the user, compromise the application, obtain sensitive information, and access or modify data.
JBlog 1.0 is vulnerable to these issues.
Exploit / POC
JBlog Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploits are available:
Attackers can use a browser to exploit these issues.
The following exploits are available:
Solution / Fix
JBlog Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
JBlog Multiple Input Validation Vulnerabilities
References:
References:
- JBlog Homepage (Muller Julien)
- JBlog 1.0 Creat Admin exploit, xss, Cookie Manipulation (s4mi)