WebGUI Username HTML Injection Vulnerability
BID:27869
Info
WebGUI Username HTML Injection Vulnerability
| Bugtraq ID: | 27869 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0940 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor reported this vulnerability. |
| Vulnerable: |
WebGUI WebGUI 7.4.23 WebGUI WebGUI 7.4.18 WebGUI WebGUI 7.4.17 WebGUI WebGUI 7.4.16 WebGUI WebGUI 7.4.15 WebGUI WebGUI 7.4.14 WebGUI WebGUI 7.4.13 WebGUI WebGUI 7.4.12 WebGUI WebGUI 7.4.11 WebGUI WebGUI 7.4.10 WebGUI WebGUI 7.4.9 WebGUI WebGUI 7.4.8 WebGUI WebGUI 7.4.7 WebGUI WebGUI 7.4.6 WebGUI WebGUI 7.4.5 WebGUI WebGUI 7.4.4 WebGUI WebGUI 7.4.3 WebGUI WebGUI 7.4.2 WebGUI WebGUI 7.4 |
| Not Vulnerable: |
WebGUI WebGUI 7.4.24 |
Discussion
WebGUI Username HTML Injection Vulnerability
WebGUI is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to WebGUI 7.4.24 are vulnerable.
WebGUI is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to WebGUI 7.4.24 are vulnerable.
Exploit / POC
Solution / Fix
WebGUI Username HTML Injection Vulnerability
Solution:
The vendor has released WebGUI 7.4.24 to address this issue. Please see the references for more information.
WebGUI WebGUI 7.4
WebGUI WebGUI 7.4.10
WebGUI WebGUI 7.4.11
WebGUI WebGUI 7.4.12
WebGUI WebGUI 7.4.13
WebGUI WebGUI 7.4.14
WebGUI WebGUI 7.4.15
WebGUI WebGUI 7.4.16
WebGUI WebGUI 7.4.17
WebGUI WebGUI 7.4.18
WebGUI WebGUI 7.4.2
WebGUI WebGUI 7.4.23
WebGUI WebGUI 7.4.3
WebGUI WebGUI 7.4.4
WebGUI WebGUI 7.4.5
WebGUI WebGUI 7.4.6
WebGUI WebGUI 7.4.7
WebGUI WebGUI 7.4.8
WebGUI WebGUI 7.4.9
Solution:
The vendor has released WebGUI 7.4.24 to address this issue. Please see the references for more information.
WebGUI WebGUI 7.4
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.10
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.11
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.12
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.13
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.14
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.15
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.16
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.17
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.18
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.2
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.23
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.3
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.4
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.5
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.6
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.7
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.8
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
WebGUI WebGUI 7.4.9
-
WebGUI webgui-7.4.24-stable.tar.gz
http://update.webgui.org/7.x.x/webgui-7.4.24-stable.tar.gz
References
WebGUI Username HTML Injection Vulnerability
References:
References:
- WebGUI 7.4.24 (stable) Released (Plain Black Software)
- WebGUI Homepage (Plain Black Software)