fuzzylime (cms) 'usercheck.php' Cross Site Scripting Vulnerability
BID:31306
Info
fuzzylime (cms) 'usercheck.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 31306 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3098 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2008 12:00AM |
| Updated: | Sep 23 2008 08:59PM |
| Credit: | Fabian Fingerle |
| Vulnerable: |
fuzzylime cms fuzzylime cms 3.0 |
| Not Vulnerable: | |
Discussion
fuzzylime (cms) 'usercheck.php' Cross Site Scripting Vulnerability
fuzzylime (cms) is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected site. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to fuzzylime (cms) 3.03 are vulnerable.
fuzzylime (cms) is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected site. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to fuzzylime (cms) 3.03 are vulnerable.
Exploit / POC
fuzzylime (cms) 'usercheck.php' Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example POST request is available:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example POST request is available:
Solution / Fix
fuzzylime (cms) 'usercheck.php' Cross Site Scripting Vulnerability
Solution:
The vendor addressed this issue in fuzzylime (cms) 3.03. Contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor addressed this issue in fuzzylime (cms) 3.03. Contact the vendor for details on obtaining the appropriate updates.
References
fuzzylime (cms) 'usercheck.php' Cross Site Scripting Vulnerability
References:
References:
- fuzzylime cms Homepage (fuzzylime cms)
- Cross Site Scripting (XSS) Vulnerabilitiy in fuzzylime (cms) >=3.02, CVE-2008-30 (Fabian Fingerle
)