RETIRED:Kronos webTA Project Management Module Multiple HTML Injection Vulnerabilities
BID:29610
Info
RETIRED:Kronos webTA Project Management Module Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 29610 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6666 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2008 12:00AM |
| Updated: | May 12 2015 07:48PM |
| Credit: | Alex Eden |
| Vulnerable: |
Kronos webTA 0 |
| Not Vulnerable: | |
Discussion
RETIRED:Kronos webTA Project Management Module Multiple HTML Injection Vulnerabilities
Kronos webTA is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
NOTE: This BID was previously titled 'Kronos webTA Project Management Module Multiple Cross Site Scripting Vulnerabilities'. Following further analysis, the title and multiple details throughout have been changed to better document the issue.
UPDATE (July 22, 2008): This BID is being retired because the initial report was based on false or misunderstood information. These vulnerabilities do not exist as specified.
Kronos webTA is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
NOTE: This BID was previously titled 'Kronos webTA Project Management Module Multiple Cross Site Scripting Vulnerabilities'. Following further analysis, the title and multiple details throughout have been changed to better document the issue.
UPDATE (July 22, 2008): This BID is being retired because the initial report was based on false or misunderstood information. These vulnerabilities do not exist as specified.
Exploit / POC
RETIRED:Kronos webTA Project Management Module Multiple HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
RETIRED:Kronos webTA Project Management Module Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED:Kronos webTA Project Management Module Multiple HTML Injection Vulnerabilities
References:
References:
- Kronos webTA Homepage (Kronos)
- webTA by kronos - XSS ("Alex Eden"
)