Cezanne Software Multiple Cross-Site Scripting Vulnerabilities
BID:28772
Info
Cezanne Software Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 28772 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1969 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Juan de la Fuente Costa and Fco Javier Puerta Rubio of S21sec |
| Vulnerable: |
Cezanne Cezanne 6.5.1 Cezanne Cezanne 7 |
| Not Vulnerable: | |
Discussion
Cezanne Software Multiple Cross-Site Scripting Vulnerabilities
Cezanne Software is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
Authenticated attackers may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow attackers to steal cookie-based authentication credentials and to launch other attacks.
Cezanne 6.5.1 and 7 are vulnerable; other versions may also be affected.
Cezanne Software is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
Authenticated attackers may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow attackers to steal cookie-based authentication credentials and to launch other attacks.
Cezanne 6.5.1 and 7 are vulnerable; other versions may also be affected.
Exploit / POC
Cezanne Software Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
Solution / Fix
Cezanne Software Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cezanne Software Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Vendor Homepage (Cezanne Software)
- S21SEC-042-en:Cezanne SW Cross-Site Scripting (login required) ("S21sec labs"
)