Textpattern 4.0.5 Multiple Security Vulnerabilities
BID:27606
Info
Textpattern 4.0.5 Multiple Security Vulnerabilities
| Bugtraq ID: | 27606 |
| Class: | Unknown |
| CVE: |
CVE-2008-5669 CVE-2008-5670 CVE-2008-5668 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Alexandr Polyakov and Stas Svistunovich of Digital Security Research Group are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
TextPattern TextPattern 4.0.5 |
| Not Vulnerable: |
TextPattern TextPattern 4.0.6 |
Discussion
Textpattern 4.0.5 Multiple Security Vulnerabilities
Textpattern is prone to multiple security vulnerabilities, including cross-site scripting issues, an HTML-injection issue, and a denial-of-service issue.
A successful exploit could allow an attacker to deny service to legitimate users, execute arbitrary HTML and script code in the context of the affected site, or execute arbitrary script code in the browser of an unsuspecting user. Other attacks are also possible.
These issues affect Textpattern 4.0.5; other versions may also be vulnerable.
Textpattern is prone to multiple security vulnerabilities, including cross-site scripting issues, an HTML-injection issue, and a denial-of-service issue.
A successful exploit could allow an attacker to deny service to legitimate users, execute arbitrary HTML and script code in the context of the affected site, or execute arbitrary script code in the browser of an unsuspecting user. Other attacks are also possible.
These issues affect Textpattern 4.0.5; other versions may also be vulnerable.
Exploit / POC
Textpattern 4.0.5 Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser. For the cross-site scripting issues, an attacker must entice an unsuspecting user to visit a malicious URI.
The following proof-of-concept URIs are available:
Attackers can exploit these issues through a browser. For the cross-site scripting issues, an attacker must entice an unsuspecting user to visit a malicious URI.
The following proof-of-concept URIs are available:
Solution / Fix
Textpattern 4.0.5 Multiple Security Vulnerabilities
Solution:
The vendor has released Textpattern 4.0.6 to address these issues. Please see the references for more information.
TextPattern TextPattern 4.0.5
Solution:
The vendor has released Textpattern 4.0.6 to address these issues. Please see the references for more information.
TextPattern TextPattern 4.0.5
-
TextPattern textpattern-4.0.6.zip
http://textpattern.com/file_download/43/textpattern-4.0.6.zip
References
Textpattern 4.0.5 Multiple Security Vulnerabilities
References:
References:
- TextPattern Web Site (TextPattern)
- [DSECRG-08-008] Textpattern 4.0.5 Multiple Security Vulnerabilities (Digital Security Research Group
)