Plone 'LiveSearch' Module HTML Injection Vulnerability
BID:27098
Info
Plone 'LiveSearch' Module HTML Injection Vulnerability
| Bugtraq ID: | 27098 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4571 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | ilmila is credited with the discovery of this vulnerability. |
| Vulnerable: |
Plone Plone 3.0.3 Plone Plone 3.0.2 Plone Plone 3.0.1 Plone Plone 2.5.4 Plone Plone 2.5.1 Plone Plone 2.1.2 Plone Plone 2.0.5 Plone Plone 2.0.4 Plone Plone 3.0 Plone Plone 2.5-beta1 Plone Plone 2.5 |
| Not Vulnerable: |
Plone Plone 3.0.4 |
Discussion
Plone 'LiveSearch' Module HTML Injection Vulnerability
Plone is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data before using it in dynamically generated content.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
This issue affects Plone 3.0.3 and prior versions.
Plone is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data before using it in dynamically generated content.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
This issue affects Plone 3.0.3 and prior versions.
Exploit / POC
Plone 'LiveSearch' Module HTML Injection Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Plone 'LiveSearch' Module HTML Injection Vulnerability
Solution:
The vendor released Plone 3.0.4 to address this issue. Please see the references for more information.
Plone Plone 3.0.3
Solution:
The vendor released Plone 3.0.4 to address this issue. Please see the references for more information.
Plone Plone 3.0.3
-
Plone Plone-3.0.4-UnifiedInstaller.tar.gz
https://launchpad.net/plone/3.0/3.0.4/+download/Plone-3.0.4-UnifiedIns taller.tar.gz -
Plone Plone-3.0.4.exe
https://launchpad.net/plone/3.0/3.0.4/+download/Plone-3.0.4.exe
References
Plone 'LiveSearch' Module HTML Injection Vulnerability
References:
References:
- Plone Homepage (Plone)
- Possible XSS into LiveSearch module (ilmila)