ikiwiki 'htmlscrubber' And 'meta' Plugins Multiple HTML Injection Vulnerabilities
BID:27760
Info
ikiwiki 'htmlscrubber' And 'meta' Plugins Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 27760 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0808 CVE-2008-0809 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | Mar 18 2008 03:01PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
ikiwiki ikiwiki 2.31 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
ikiwiki ikiwiki 2.31.1 |
Discussion
ikiwiki 'htmlscrubber' And 'meta' Plugins Multiple HTML Injection Vulnerabilities
'ikiwiki' is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
'ikiwiki' 2.31.0 is vulnerable; prior versions may also be affected.
'ikiwiki' is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
'ikiwiki' 2.31.0 is vulnerable; prior versions may also be affected.
Exploit / POC
ikiwiki 'htmlscrubber' And 'meta' Plugins Multiple HTML Injection Vulnerabilities
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ikiwiki 'htmlscrubber' And 'meta' Plugins Multiple HTML Injection Vulnerabilities
Solution:
The vendor released ikiwiki 2.31.1 to address these issues. Please see the references for more information.
Solution:
The vendor released ikiwiki 2.31.1 to address these issues. Please see the references for more information.
References
ikiwiki 'htmlscrubber' And 'meta' Plugins Multiple HTML Injection Vulnerabilities
References:
References:
- javascript insertion via uris (ikiwiki)
- Vendor Homepage (ikiwiki)