Meridio Document and Records Management 'Title' Parameter Multiple HTML Injection Vulnerabilities
BID:27721
Info
Meridio Document and Records Management 'Title' Parameter Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 27721 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7231 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | R Dominguez Vega of MWR InfoSecurity is credited with discovering these vulnerabilities. |
| Vulnerable: |
Meridio Meridio Document and Records Management 4.3 |
| Not Vulnerable: |
Meridio Meridio Document and Records Management 4.3 SR1 |
Discussion
Meridio Document and Records Management 'Title' Parameter Multiple HTML Injection Vulnerabilities
Meridio Document and Records Management is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to Meridio Document and Records Management 4.3 SR1 are vulnerable.
Meridio Document and Records Management is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to Meridio Document and Records Management 4.3 SR1 are vulnerable.
Exploit / POC
Meridio Document and Records Management 'Title' Parameter Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Meridio Document and Records Management 'Title' Parameter Multiple HTML Injection Vulnerabilities
Solution:
The vendor has addressed these issues in Document and Records Management 4.3 SR1. Please contact the vendor for information on obtaining and applying the updates.
Solution:
The vendor has addressed these issues in Document and Records Management 4.3 SR1. Please contact the vendor for information on obtaining and applying the updates.
References
Meridio Document and Records Management 'Title' Parameter Multiple HTML Injection Vulnerabilities
References:
References:
- Meridio Advisory Released (MWR InfoSecurity)
- Meridio Document and Records Management Homepage (Meridio)