WebCalendar Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
BID:27461
Info
WebCalendar Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 27461 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6696 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Omer Singer of The DigiTrust Group is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
WebCalendar WebCalendar 1.1.6 |
| Not Vulnerable: | |
Discussion
WebCalendar Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
WebCalendar is prone to multiple HTML-injection and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials. The attacker could also exploit the HTML-injection issues to control how the site is rendered to the user; other attacks are also possible.
These issues affect WebCalendar 1.1.6; other versions may also be vulnerable.
WebCalendar is prone to multiple HTML-injection and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials. The attacker could also exploit the HTML-injection issues to control how the site is rendered to the user; other attacks are also possible.
These issues affect WebCalendar 1.1.6; other versions may also be vulnerable.
Exploit / POC
WebCalendar Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
An attacker can exploit the HTML-injection issue via a browser. The attacker must trick a victim into following a malicious URI to exploit the cross-site scripting issues.
The following proof-of-concept URIs are available:
An attacker can exploit the HTML-injection issue via a browser. The attacker must trick a victim into following a malicious URI to exploit the cross-site scripting issues.
The following proof-of-concept URIs are available:
Solution / Fix
WebCalendar Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WebCalendar Multiple HTML Injection and Cross-Site Scripting Vulnerabilities
References:
References:
- The DigiTrust Group: Advisory #071214b - WebCalendar Multiple Persistent and Non (The DigiTrust Group)
- WebCalendar Home Page (WebCalendar)