Feed to JavaScript Feed2JS Feed URI Cross Site Scripting Vulnerability
BID:26518
Info
Feed to JavaScript Feed2JS Feed URI Cross Site Scripting Vulnerability
| Bugtraq ID: | 26518 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2007 12:00AM |
| Updated: | Nov 21 2007 05:14PM |
| Credit: | JVN reported this vulnerability. |
| Vulnerable: |
Feed to JavaScript Feed2JS 1.91 |
| Not Vulnerable: |
Feed to JavaScript Feed2JS 1.93 Feed to JavaScript Feed2JS 1.92 |
Discussion
Feed to JavaScript Feed2JS Feed URI Cross Site Scripting Vulnerability
Feed to JavaScript (Feed2JS) is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue affects Feed2JS 1.91; other versions may also be vulnerable.
Feed to JavaScript (Feed2JS) is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue affects Feed2JS 1.91; other versions may also be vulnerable.
Exploit / POC
Feed to JavaScript Feed2JS Feed URI Cross Site Scripting Vulnerability
An attacker must entice an unsuspecting victim into following a malicious URI to exploit this issue.
An attacker must entice an unsuspecting victim into following a malicious URI to exploit this issue.
Solution / Fix
Feed to JavaScript Feed2JS Feed URI Cross Site Scripting Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Feed to JavaScript Feed2JS 1.91
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Feed to JavaScript Feed2JS 1.91
-
Feed to JavaScript feed2js 1.93
http://eduforge.org/frs/?group_id=119&release_id=331
References
Feed to JavaScript Feed2JS Feed URI Cross Site Scripting Vulnerability
References:
References:
- Feed to JavaScript Homepage (Feed to JavaScript)
- Feed2JS 1.92 Minor Patch Note (Feed to JavaScript)
- JVN#33218020 (JVN)