FileMaker Instant Web Publishing Cross Site Scripting Vulnerability
BID:26515
Info
FileMaker Instant Web Publishing Cross Site Scripting Vulnerability
| Bugtraq ID: | 26515 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6104 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2007 12:00AM |
| Updated: | Dec 18 2007 08:06PM |
| Credit: | JVN reported this vulnerability. |
| Vulnerable: |
FileMaker FileMaker Server 8.0 Advanced FileMaker FileMaker Server 8.0 FileMaker FileMaker Server 7.0 FileMaker FileMaker Pro 8.5 FileMaker FileMaker Pro 8.0 Advanced FileMaker FileMaker Pro 8.0 FileMaker FileMaker Pro 7.0 FileMaker FileMaker Developer 7 |
| Not Vulnerable: | |
Discussion
FileMaker Instant Web Publishing Cross Site Scripting Vulnerability
FileMaker is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
Exploiting this issue allows an attacker to execute arbitrary HTML or script code in a user's browser session in the context of an affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue affects the following versions of FileMaker:
FileMaker Pro 7
FileMaker Developer 7
FileMaker Server 7
FileMaker Pro 8.x
FileMaker Pro 8.x Advanced
FileMaker Server 8.x
FileMaker Server 8.x Advanced
FileMaker is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
Exploiting this issue allows an attacker to execute arbitrary HTML or script code in a user's browser session in the context of an affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue affects the following versions of FileMaker:
FileMaker Pro 7
FileMaker Developer 7
FileMaker Server 7
FileMaker Pro 8.x
FileMaker Pro 8.x Advanced
FileMaker Server 8.x
FileMaker Server 8.x Advanced
Exploit / POC
FileMaker Instant Web Publishing Cross Site Scripting Vulnerability
An attacker must entice an unsuspecting victim into following a malicious URI to exploit this issue.
An attacker must entice an unsuspecting victim into following a malicious URI to exploit this issue.
Solution / Fix
FileMaker Instant Web Publishing Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FileMaker Instant Web Publishing Cross Site Scripting Vulnerability
References:
References:
- FileMaker Homepage (FileMaker)
- JVN#55833292 (JVN)