refbase 'headerMsg' Parameter Cross Site Scripting Vulnerabilities
BID:32372
Info
refbase 'headerMsg' Parameter Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 32372 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6400 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | refbase |
| Vulnerable: |
refbase refbase 0.9 |
| Not Vulnerable: |
refbase refbase 0.9.5 |
Discussion
refbase 'headerMsg' Parameter Cross Site Scripting Vulnerabilities
The 'refbase' program is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Versions prior to refbase 0.9.5 are vulnerable.
The 'refbase' program is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Versions prior to refbase 0.9.5 are vulnerable.
Exploit / POC
refbase 'headerMsg' Parameter Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
refbase 'headerMsg' Parameter Cross Site Scripting Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
refbase refbase 0.9
Solution:
The vendor has released an update. Please see the references for more information.
refbase refbase 0.9
-
refbase refbase-0.9.5.tar.gz
http://downloads.sourceforge.net/refbase/refbase-0.9.5.tar.gz?modtime= 1227137333&big_mirror=0
References
refbase 'headerMsg' Parameter Cross Site Scripting Vulnerabilities
References:
References:
- refbase Homepage (refbase)
- refbase-0.9.5 Changelog (refbase)