WiKID wClient-PHP 'sample.php' Cross-Site Scripting Vulnerability
BID:28740
Info
WiKID wClient-PHP 'sample.php' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 28740 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4763 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2008 12:00AM |
| Updated: | Apr 16 2015 06:01PM |
| Credit: | Francesco "ascii" Ongaro and Antonio "s4tan" Parata |
| Vulnerable: |
WiKID Systems wClient-PHP 3.0-2 WiKID Systems wClient-PHP 3.0-1 |
| Not Vulnerable: |
WiKID Systems wClient-PHP 3.0-3 |
Discussion
WiKID wClient-PHP 'sample.php' Cross-Site Scripting Vulnerability
WiKID wClient-PHP is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to WiKID wClient-PHP 3.0-3 are affected.
WiKID wClient-PHP is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to WiKID wClient-PHP 3.0-3 are affected.
Exploit / POC
Solution / Fix
WiKID wClient-PHP 'sample.php' Cross-Site Scripting Vulnerability
Solution:
The vendor released wClient-PHP 3.0-3 to address this issue. Please see the references for more information.
WiKID Systems wClient-PHP 3.0-1
WiKID Systems wClient-PHP 3.0-2
Solution:
The vendor released wClient-PHP 3.0-3 to address this issue. Please see the references for more information.
WiKID Systems wClient-PHP 3.0-1
-
WiKID Systems wClient-PHP-3.0-3.tar.gz
http://www.wikidsystems.com/webdemo/wClient-PHP-3.0-3.tar.gz
WiKID Systems wClient-PHP 3.0-2
-
WiKID Systems wClient-PHP-3.0-3.tar.gz
http://www.wikidsystems.com/webdemo/wClient-PHP-3.0-3.tar.gz
References
WiKID wClient-PHP 'sample.php' Cross-Site Scripting Vulnerability
References:
References:
- Potential XSS in PHP Sample page (WiKID Systems)
- Vendor Homepage (WiKID Systems)
- WiKID wClient-PHP <= 3.0-2 Multiple XSS Vulnerabilities (ascii
)