FatWire Content Server Multiple Cross-Site Scripting Vulnerabilities
BID:26472
Info
FatWire Content Server Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 26472 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5932 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2007 12:00AM |
| Updated: | Mar 13 2008 03:11AM |
| Credit: | Andrew Davies of Portcullis Computer Security Ltd is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
FatWire Content Server 6.3 |
| Not Vulnerable: |
FatWire Content Server 7.0.3 |
Discussion
FatWire Content Server Multiple Cross-Site Scripting Vulnerabilities
FatWire Content Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
FatWire Content Server 6.3 is vulnerable; other versions may also be affected.
FatWire Content Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
FatWire Content Server 6.3 is vulnerable; other versions may also be affected.
Exploit / POC
FatWire Content Server Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
FatWire Content Server Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor released a patch for Content Server 6.3 to address this issue. Reports indicate that Content Server 7.0.3 is unaffected by this issue. Please contact the vendor for information on how to obtain and apply patches or upgrades.
Solution:
The vendor released a patch for Content Server 6.3 to address this issue. Reports indicate that Content Server 7.0.3 is unaffected by this issue. Please contact the vendor for information on how to obtain and apply patches or upgrades.
References
FatWire Content Server Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- FatWire Homapage (FatWire)
- Portcullis Security Advisory 07_012 (Portcullis Computer Security)