Kaya CGI Framework HTTP Header Cross Site Scripting Vulnerability
BID:29476
Info
Kaya CGI Framework HTTP Header Cross Site Scripting Vulnerability
| Bugtraq ID: | 29476 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6428 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2008 12:00AM |
| Updated: | Jun 02 2008 12:00AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Durham University Computing Society Kaya 0.4 |
| Not Vulnerable: |
Durham University Computing Society Kaya 0.4.1 |
Discussion
Kaya CGI Framework HTTP Header Cross Site Scripting Vulnerability
Kaya is prone to a cross-site scripting vulnerability because the software fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects Kaya 0.4.0; other versions may also be vulnerable.
Kaya is prone to a cross-site scripting vulnerability because the software fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects Kaya 0.4.0; other versions may also be vulnerable.
Exploit / POC
Kaya CGI Framework HTTP Header Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Kaya CGI Framework HTTP Header Cross Site Scripting Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Durham University Computing Society Kaya 0.4
Solution:
The vendor has released fixes. Please see the references for more information.
Durham University Computing Society Kaya 0.4
-
Durham University Computing Society kaya-0.4.1.tgz
http://kayalang.org/src/kaya-0.4.1.tgz
References
Kaya CGI Framework HTTP Header Cross Site Scripting Vulnerability
References:
References:
- 26 May 2008: Kaya 0.4.1 and 0.5.0 released (Durham University Computing Societ)
- Kaya Homepage (Durham University Computing Societ)