Silva 'fulltext' Parameter Cross Site Scripting Vulnerability
BID:32183
Info
Silva 'fulltext' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 32183 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5786 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | Russ McRee, HolisticInfoSec |
| Vulnerable: |
Infrae Silva 2.1 Infrae Silva 2.0 Infrae Silva 1.6 |
| Not Vulnerable: |
Infrae Silva 2.1.0.2 Infrae Silva 2.0.12.2 Infrae Silva 1.6.3.2 |
Discussion
Silva 'fulltext' Parameter Cross Site Scripting Vulnerability
Silva is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Silva is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Silva 'fulltext' Parameter Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Silva 'fulltext' Parameter Cross Site Scripting Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Silva 'fulltext' Parameter Cross Site Scripting Vulnerability
References:
References:
- HIO-2008-1027 Silva CMS SilvaFind 1.1.3 XSS (Russ McRee, HolisticInfoSec)
- Vendor Homepage (Infrae)