Aardvark Topsites PHP 'index.php' Cross Site Scripting Vulnerability
BID:35506
Info
Aardvark Topsites PHP 'index.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 35506 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2009 12:00AM |
| Updated: | Jun 29 2009 03:59PM |
| Credit: | José Pablo González |
| Vulnerable: |
Aardvark Topsites PHP Aardvark Topsites PHP 5.2 |
| Not Vulnerable: | |
Discussion
Aardvark Topsites PHP 'index.php' Cross Site Scripting Vulnerability
Aardvark Topsites PHP is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Aardvark Topsites PHP 5.2.0 is vulnerable; other versions may also be affected.
Aardvark Topsites PHP is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Aardvark Topsites PHP 5.2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Aardvark Topsites PHP 'index.php' Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/index.php?a=search&q=psstt+securityâ~@~]><a+href%3Dhttp%3A%2F%2Fwebsec.id3as.com>Web-Application-Security
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/index.php?a=search&q=psstt+securityâ~@~]><a+href%3Dhttp%3A%2F%2Fwebsec.id3as.com>Web-Application-Security
Solution / Fix
Aardvark Topsites PHP 'index.php' Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Aardvark Topsites PHP 'index.php' Cross Site Scripting Vulnerability
References:
References:
- Aardvark Topsites PHP Homepage (Aardvark Topsites PHP)
- Report vulnerabilities (JP
)