Avant Browser and Orca Browser 'browser:home' Multiple HTML Injection Vulnerabilities
BID:35898
Info
Avant Browser and Orca Browser 'browser:home' Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 35898 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2009 12:00AM |
| Updated: | Sep 09 2010 09:52PM |
| Credit: | Lostmon |
| Vulnerable: |
Avant Browser Avant Browser 11.7 build 35 |
| Not Vulnerable: |
Avant Browser Avant Browser 11.7 build 36 |
Discussion
Avant Browser and Orca Browser 'browser:home' Multiple HTML Injection Vulnerabilities
Avant Browser and Orca Browser are prone to multiple HTML-injection vulnerabilities because the applications fail to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
The following are vulnerable:
Avant Browser 11.7 build 35; other versions may also be affected.
Versions prior to Orca Browser 1.2 Build 3
Avant Browser and Orca Browser are prone to multiple HTML-injection vulnerabilities because the applications fail to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
The following are vulnerable:
Avant Browser 11.7 build 35; other versions may also be affected.
Versions prior to Orca Browser 1.2 Build 3
Exploit / POC
Avant Browser and Orca Browser 'browser:home' Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Avant Browser and Orca Browser 'browser:home' Multiple HTML Injection Vulnerabilities
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
Avant Browser and Orca Browser 'browser:home' Multiple HTML Injection Vulnerabilities
References:
References:
- Avant Browser 11.7 Build 36, Released 8.10.2009 (Avant Browser)
- Avant Browser browser:home Persistent XSS vulnerabilities (Lostmon)
- Avant Browser Homepage (Avant Browser)
- Orca Browser 1.2 Build 3 Released (Orca Browser)
- Orca Browser Homepage (Orca Browser)