Savvy Content Manager 'searchterms' Parameter Multiple Cross Site Scripting Vulnerabilities
BID:28200
Info
Savvy Content Manager 'searchterms' Parameter Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 28200 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1306 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Russ McRee is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Savvy Software Savvy Content Manager 0 |
| Not Vulnerable: | |
Discussion
Savvy Content Manager 'searchterms' Parameter Multiple Cross Site Scripting Vulnerabilities
Savvy Content Manager is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Savvy Content Manager is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Savvy Content Manager 'searchterms' Parameter Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Savvy Content Manager 'searchterms' Parameter Multiple Cross Site Scripting Vulnerabilities
Solution:
The vendor has released fixes. Please see the references for more information.
Savvy Software Savvy Content Manager 0
Solution:
The vendor has released fixes. Please see the references for more information.
Savvy Software Savvy Content Manager 0
-
Savvy Software savvysecurityfix.zip
http://www.besavvy.com/uploads/savvysecurityfix.zip
References
Savvy Content Manager 'searchterms' Parameter Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Savvy Content Manager Homepage (Savvy Software)
- Security Patch Savvy Content Manager (Savvy Software)