Fantastico Cross-Site Scripting Vulnerabilities and Local File Include Vulnerability
BID:32016
Info
Fantastico Cross-Site Scripting Vulnerabilities and Local File Include Vulnerability
| Bugtraq ID: | 32016 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6926 CVE-2008-6927 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2008 12:00AM |
| Updated: | Jul 06 2016 02:18PM |
| Credit: | Khashayar Fereidani |
| Vulnerable: |
Netenberg Fantastico 0 |
| Not Vulnerable: | |
Discussion
Fantastico Cross-Site Scripting Vulnerabilities and Local File Include Vulnerability
Fantastico is prone to multiple cross-site scripting vulnerabilities and a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerability to access potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer.
The attacker can exploit the cross-site scripting vulnerabilities to execute arbitrary script code within the context of the affected site and steal cookie-based authentication credentials.
Fantastico is prone to multiple cross-site scripting vulnerabilities and a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerability to access potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer.
The attacker can exploit the cross-site scripting vulnerabilities to execute arbitrary script code within the context of the affected site and steal cookie-based authentication credentials.
Exploit / POC
Fantastico Cross-Site Scripting Vulnerabilities and Local File Include Vulnerability
An attacker can exploit these issues with a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into following a malicious URI.
The following proofs of concept are available:
An attacker can exploit these issues with a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into following a malicious URI.
The following proofs of concept are available:
Solution / Fix
Fantastico Cross-Site Scripting Vulnerabilities and Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Fantastico Cross-Site Scripting Vulnerabilities and Local File Include Vulnerability
References:
References: