glFusion Anonymous Comment 'username' Field HTML Injection Vulnerability
BID:33683
Info
glFusion Anonymous Comment 'username' Field HTML Injection Vulnerability
| Bugtraq ID: | 33683 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0455 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2009 12:00AM |
| Updated: | Feb 11 2009 05:18PM |
| Credit: | FortConsult�??s Security Research Team/Bjarne Mathiesen Schacht |
| Vulnerable: |
glFusion glFusion 1.1.1 glFusion glFusion 1.1 |
| Not Vulnerable: | |
Discussion
glFusion Anonymous Comment 'username' Field HTML Injection Vulnerability
glFusion is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
glFusion 1.1.0 and 1.1.1 are vulnerable; other versions may also be affected.
glFusion is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
glFusion 1.1.0 and 1.1.1 are vulnerable; other versions may also be affected.
Exploit / POC
glFusion Anonymous Comment 'username' Field HTML Injection Vulnerability
Attackers can use a browser to exploit these issues.
The following example HTTP request is available:
Attackers can use a browser to exploit these issues.
The following example HTTP request is available:
Solution / Fix
glFusion Anonymous Comment 'username' Field HTML Injection Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
glFusion glFusion 1.1
glFusion glFusion 1.1.1
Solution:
The vendor has released updates. Please contact the vendor for details.
glFusion glFusion 1.1
-
glFusion private/system/lib-comment.php
http://glfusion.svn.sourceforge.net/viewvc/glfusion/glfusion/releases/ release-1.1.1/private/system/lib-comment.php?revision=3841
glFusion glFusion 1.1.1
-
glFusion private/system/lib-comment.php
http://glfusion.svn.sourceforge.net/viewvc/glfusion/glfusion/releases/ release-1.1.1/private/system/lib-comment.php?revision=3841
References
glFusion Anonymous Comment 'username' Field HTML Injection Vulnerability
References:
References:
- glFusion CMS�??�??Comment�?� Cross-Site scripting Vulnerability (FortConsult)
- glFusion Homepage (glFusion)
- Potential XSS Issue with Anonymous Comments (glFusion)