Dotclear Unspecified Cross-Site Scripting Vulnerability
BID:34036
Info
Dotclear Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 34036 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2009 12:00AM |
| Updated: | Mar 09 2009 04:26PM |
| Credit: | Julien |
| Vulnerable: |
Dotclear Dotclear 2.1.4 Dotclear Dotclear 2.1.3 |
| Not Vulnerable: |
Dotclear Dotclear 2.1.5 |
Discussion
Dotclear Unspecified Cross-Site Scripting Vulnerability
Dotclear is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Dotclear 2.1.5 are vulnerable.
Dotclear is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Dotclear 2.1.5 are vulnerable.
Exploit / POC
Dotclear Unspecified Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Dotclear Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Dotclear Unspecified Cross-Site Scripting Vulnerability
References:
References:
- Dotclear 2.1.5 (Dotclear)
- Dotclear Homepage (Dotclear)