PHPkrm Unspecified Cross Site Scripting Vulnerability
BID:28510
Info
PHPkrm Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 28510 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1629 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2008 12:00AM |
| Updated: | Apr 16 2015 06:04PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
PHPkrm PHPkrm 1.4.2 |
| Not Vulnerable: |
PHPkrm PHPkrm 1.5 |
Discussion
PHPkrm Unspecified Cross Site Scripting Vulnerability
PHPkrm is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help an attacker steal cookie-based authentication credentials and launch other attacks.
PHPkrm 1.4.2 is vulnerable to this issue; other versions may also be affected.
PHPkrm is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help an attacker steal cookie-based authentication credentials and launch other attacks.
PHPkrm 1.4.2 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
PHPkrm Unspecified Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
PHPkrm Unspecified Cross Site Scripting Vulnerability
Solution:
The vendor has released PHPkrm 1.5.0. Please see the references for more information.
PHPkrm PHPkrm 1.4.2
Solution:
The vendor has released PHPkrm 1.5.0. Please see the references for more information.
PHPkrm PHPkrm 1.4.2
-
PHPkrm phpkrm-1.5.0.tar.bz2
http://phpkrm.googlecode.com/files/phpkrm-1.5.0.tar.bz2