Agavi Multiple Cross Site Scripting Vulnerabilities
BID:33826
Info
Agavi Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 33826 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0417 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2009 12:00AM |
| Updated: | Feb 20 2009 05:27PM |
| Credit: | Daniel Kubitza |
| Vulnerable: |
Agavi Agavi 1.0 beta 7 Agavi Agavi 1.0 beta 5 Agavi Agavi 0.11.6-RC2 |
| Not Vulnerable: |
Agavi Agavi 1.0 beta 8 Agavi Agavi 0.11.6 |
Discussion
Agavi Multiple Cross Site Scripting Vulnerabilities
Agavi is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Agavi is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Exploit / POC
Agavi Multiple Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Agavi Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Agavi Multiple Cross Site Scripting Vulnerabilities
References:
References: