Eggblog Rss.PHP Cross-Site Scripting Vulnerability
BID:26408
Info
Eggblog Rss.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 26408 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5980 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2007 12:00AM |
| Updated: | Nov 22 2007 11:34PM |
| Credit: | Mesut Timur <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Eggblog Eggblog 3.1 |
| Not Vulnerable: |
Eggblog Eggblog 3.1.1 |
Discussion
Eggblog Rss.PHP Cross-Site Scripting Vulnerability
Eggblog is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker to steal cookie-based authentication credentials and to launch other attacks.
Eggblog 3.1.0 is vulnerable; other versions may also be affected.
Eggblog is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker to steal cookie-based authentication credentials and to launch other attacks.
Eggblog 3.1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Eggblog Rss.PHP Cross-Site Scripting Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
Solution / Fix
Eggblog Rss.PHP Cross-Site Scripting Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
Eggblog Eggblog 3.1
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
Eggblog Eggblog 3.1
-
Eggblog eggblog 3.1.1
http://sourceforge.net/project/showfiles.php?group_id=155425
References
Eggblog Rss.PHP Cross-Site Scripting Vulnerability
References:
References:
- Eggblog 3.1.1 Release Notes (Eggblog)
- Vendor Home Page (EggBlog)
- Eggblog v3.1.0 XSS Vulnerability ([email protected])