Multiple Scripts For Sites EZ Products 'directory.php' Cross Site Scripting Vulnerability
BID:33688
Info
Multiple Scripts For Sites EZ Products 'directory.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 33688 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2009 12:00AM |
| Updated: | Feb 11 2009 06:38PM |
| Credit: | Cru3l.b0y |
| Vulnerable: |
Scripts for Sites EZ Virtual Properties 0 Scripts for Sites EZ Restaurant 0 Scripts for Sites EZ Redirection 0 Scripts for Sites EZ Recipe 0 Scripts for Sites EZ Real Estate 0 Scripts for Sites EZ mlm 0 Scripts for Sites EZ Link Directory 0 Scripts for Sites EZ Hosting Index 0 Scripts for Sites EZ Home Business Directory 0 Scripts for Sites EZ Guestbook 0 Scripts for Sites EZ Gaming Directory 0 Scripts for Sites EZ Exit Exchange 0 Scripts for Sites EZ Classifieds 0 Scripts for Sites EZ Career 0 Scripts for Sites EZ Car Dealer 0 Scripts for Sites EZ BIZ Pro 0 Scripts for Sites EZ Affiliate 0 Scripts for Sites EZ Adult Directory 0 |
| Not Vulnerable: | |
Discussion
Multiple Scripts For Sites EZ Products 'directory.php' Cross Site Scripting Vulnerability
Multiple Scripts For Sites products are prone to a cross-site scripting vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Multiple Scripts For Sites products are prone to a cross-site scripting vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Multiple Scripts For Sites EZ Products 'directory.php' Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
Multiple Scripts For Sites EZ Products 'directory.php' Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Scripts For Sites EZ Products 'directory.php' Cross Site Scripting Vulnerability
References:
References:
- Scripts For Sites Homepage (Scripts For Sites)