Geeklog mycaljp Plugin Cross Site Scripting Vulnerability
BID:36095
Info
Geeklog mycaljp Plugin Cross Site Scripting Vulnerability
| Bugtraq ID: | 36095 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2009 12:00AM |
| Updated: | Aug 21 2009 05:32PM |
| Credit: | Oono Masako |
| Vulnerable: |
Geeklog mycaljp Plugin 2.0.6 Geeklog Geeklog (Extended Japanese Package) 1.5.2 |
| Not Vulnerable: |
Geeklog mycaljp Plugin 2.0.7 Geeklog Geeklog (Extended Japanese Package) 2009-06-29 |
Discussion
Geeklog mycaljp Plugin Cross Site Scripting Vulnerability
The 'mycaljp' plugin for Geeklog is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This issue affects versions prior to mycaljp 2.0.7.
The 'mycaljp' plugin for Geeklog is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This issue affects versions prior to mycaljp 2.0.7.
Exploit / POC
Geeklog mycaljp Plugin Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Geeklog mycaljp Plugin Cross Site Scripting Vulnerability
Solution:
The vendor has released update. Please see the references for details.
Geeklog mycaljp Plugin 2.0.6
Solution:
The vendor has released update. Please see the references for details.
Geeklog mycaljp Plugin 2.0.6
-
Geeklog mycaljp_2.0.7_1.4.1.tar.gz
http://www.geeklog.jp/filemgmt_data/files/mycaljp_2.0.7_1.4.1.tar.gz
References
Geeklog mycaljp Plugin Cross Site Scripting Vulnerability
References:
References: