Flyspray Multiple Information Disclosure, HTML Injection, and Cross-Site Scripting Vulnerabilities
BID:28076
Info
Flyspray Multiple Information Disclosure, HTML Injection, and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 28076 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2008 12:00AM |
| Updated: | Mar 03 2008 08:32PM |
| Credit: | Digital Security Research Group is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Flyspray Flyspray 0.9.9 2 Flyspray Flyspray 0.9.9 .4 Flyspray Flyspray 0.9.9 .3 Flyspray Flyspray 0.9.9 Flyspray Flyspray 0.9.9.1 |
| Not Vulnerable: |
Flyspray Flyspray 0.9.9 .5 |
Discussion
Flyspray Multiple Information Disclosure, HTML Injection, and Cross-Site Scripting Vulnerabilities
Flyspray is prone to an information-disclosure issue, an HTML-injection issue, and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues determine valid usernames and passwords via brute-force attacks or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, and launch other attacks.
These issues affect Flyspray 0.9.9 to 0.9.9.4.
Flyspray is prone to an information-disclosure issue, an HTML-injection issue, and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues determine valid usernames and passwords via brute-force attacks or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, and launch other attacks.
These issues affect Flyspray 0.9.9 to 0.9.9.4.
Exploit / POC
Flyspray Multiple Information Disclosure, HTML Injection, and Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues via a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
The following proof-of-concept URIs are available:
Attackers can exploit these issues via a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
The following proof-of-concept URIs are available:
Solution / Fix
Flyspray Multiple Information Disclosure, HTML Injection, and Cross-Site Scripting Vulnerabilities
Solution:
The vendor released Flyspray 0.9.9.5 to address these issues. Please see the references for more information.
Flyspray Flyspray 0.9.9.1
Flyspray Flyspray 0.9.9
Flyspray Flyspray 0.9.9 2
Flyspray Flyspray 0.9.9 .4
Flyspray Flyspray 0.9.9 .3
Solution:
The vendor released Flyspray 0.9.9.5 to address these issues. Please see the references for more information.
Flyspray Flyspray 0.9.9.1
-
Flyspray flyspray-0.9.9.5.zip
http://flyspray.org/flyspray-0.9.9.5.zip
Flyspray Flyspray 0.9.9
-
Flyspray flyspray-0.9.9.5.zip
http://flyspray.org/flyspray-0.9.9.5.zip
Flyspray Flyspray 0.9.9 2
-
Flyspray flyspray-0.9.9.5.zip
http://flyspray.org/flyspray-0.9.9.5.zip
Flyspray Flyspray 0.9.9 .4
-
Flyspray flyspray-0.9.9.5.zip
http://flyspray.org/flyspray-0.9.9.5.zip
Flyspray Flyspray 0.9.9 .3
-
Flyspray flyspray-0.9.9.5.zip
http://flyspray.org/flyspray-0.9.9.5.zip
References
Flyspray Multiple Information Disclosure, HTML Injection, and Cross-Site Scripting Vulnerabilities
References:
References:
- Flyspray Cross Site Scripting Vulnerabilities (2008-02-11) (Flyspray)
- Flyspray Homepage (Flyspray )
- [DSECRG-08-017] Flyspray 0.9.9.4 Multiple Security Vulnerabilities (Digital Security Research Group
)