Adobe JRun Multiple Unspecified Cross Site Scripting Vulnerabilities
BID:36050
Info
Adobe JRun Multiple Unspecified Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 36050 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-1874 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2009 12:00AM |
| Updated: | Oct 06 2009 03:49PM |
| Credit: | Alexandr Polyakov of Digital Security Research Group |
| Vulnerable: |
Macromedia JRun 4.0 SP1a Macromedia JRun 4.0 SP1 Macromedia JRun 4.0 build 61650 Macromedia JRun 4.0 CGISCRIPT.NET csNews 4.0 Adobe JRun 4.0 Updater 7 Adobe JRun 4.0 Updater 6 |
| Not Vulnerable: | |
Discussion
Adobe JRun Multiple Unspecified Cross Site Scripting Vulnerabilities
Adobe JRun is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Very few details are available regarding these issues. We will update this BID as more information emerges.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
JRun 4.0 is vulnerable; other versions may also be affected.
Adobe JRun is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Very few details are available regarding these issues. We will update this BID as more information emerges.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
JRun 4.0 is vulnerable; other versions may also be affected.
Exploit / POC
Adobe JRun Multiple Unspecified Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Adobe JRun Multiple Unspecified Cross Site Scripting Vulnerabilities
Solution:
Updates are available; please see the references for details.
Adobe JRun 4.0 Updater 6
Adobe JRun 4.0 Updater 7
Macromedia JRun 4.0 build 61650
Macromedia JRun 4.0 SP1
CGISCRIPT.NET csNews 4.0
Macromedia JRun 4.0
Macromedia JRun 4.0 SP1a
Solution:
Updates are available; please see the references for details.
Adobe JRun 4.0 Updater 6
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear -
Adobe jmc-app2.zip
http://download.macromedia.com/pub/coldfusion/updates/jmc-app2.zip
Adobe JRun 4.0 Updater 7
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear -
Adobe jmc-app2.zip
http://download.macromedia.com/pub/coldfusion/updates/jmc-app2.zip
Macromedia JRun 4.0 build 61650
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear
Macromedia JRun 4.0 SP1
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear
CGISCRIPT.NET csNews 4.0
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear
Macromedia JRun 4.0
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear
Macromedia JRun 4.0 SP1a
-
Adobe jmc-app.ear
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear
References
Adobe JRun Multiple Unspecified Cross Site Scripting Vulnerabilities
References:
References:
- [DSECRG-09-051] Adobe JRun 4 - Multiple XSS vulnerabilities (Digital Security Research Group)
- Installation instructions for CVE-2009-1873 and CVE-2009-1874 (Adobe)
- JRun Homepage (Adobe)
- ReadMe_1873_1874b (Adobe)
- [DSECRG-09-051] Adobe JRun 4 Multiple XSS ([email protected])
- Adobe - Security Bulletins: APSB09-12 Security Update: Hotfixes available for Co (Adobe)