Mambo MOStlyCE Module 'connector.php' Cross-Site Scripting Vulnerability
BID:27470
Info
Mambo MOStlyCE Module 'connector.php' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 27470 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7213 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | AmnPardaz Security Research Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mambo MOStlyCE 2.4 |
| Not Vulnerable: |
Mambo MOStlyCE 3.0 |
Discussion
Mambo MOStlyCE Module 'connector.php' Cross-Site Scripting Vulnerability
The MOStlyCE module for Mambo is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
MOStlyCE 2.4 included with Mambo 4.6.3 is vulnerable; other versions may also be affected.
The MOStlyCE module for Mambo is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
MOStlyCE 2.4 included with Mambo 4.6.3 is vulnerable; other versions may also be affected.
Exploit / POC
Mambo MOStlyCE Module 'connector.php' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
Solution / Fix
Mambo MOStlyCE Module 'connector.php' Cross-Site Scripting Vulnerability
Solution:
Mambo released MOStlyCE 3.0 to address this issue. Please see the references for more information.
Mambo MOStlyCE 2.4
Solution:
Mambo released MOStlyCE 3.0 to address this issue. Please see the references for more information.
Mambo MOStlyCE 2.4
-
Mambo mostlyceV3.0.zip
http://mambo-code.org/gf/download/frsrelease/325/604/mostlyceV3.0.zip
References
Mambo MOStlyCE Module 'connector.php' Cross-Site Scripting Vulnerability
References:
References: