Feed Sidebar RSS Feed HTML Injection Vulnerability
BID:36104
Info
Feed Sidebar RSS Feed HTML Injection Vulnerability
| Bugtraq ID: | 36104 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2009 12:00AM |
| Updated: | Aug 24 2009 09:03PM |
| Credit: | Nick Freeman |
| Vulnerable: |
Feed Sidebar Feed Sidebar 3.1 |
| Not Vulnerable: |
Feed Sidebar Feed Sidebar 3.2 |
Discussion
Feed Sidebar RSS Feed HTML Injection Vulnerability
Feed Sidebar is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Arbitrary script code supplied by the attacker would run with elevated privileges since it is rendered in with 'chrome' privileges.
This issue affects versions prior to Feed Sidebar 3.2.
Feed Sidebar is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Arbitrary script code supplied by the attacker would run with elevated privileges since it is rendered in with 'chrome' privileges.
This issue affects versions prior to Feed Sidebar 3.2.
Exploit / POC
Feed Sidebar RSS Feed HTML Injection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious RSS feed.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious RSS feed.
Solution / Fix
Feed Sidebar RSS Feed HTML Injection Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Feed Sidebar RSS Feed HTML Injection Vulnerability
References:
References:
- Feed Sidebar (Mozilla Firefox Extension) �?? Code Injection Vulnerability (Security-Assessment.com)
- Feed Sidebar Homepage (Feed Sidebar)
- Feed Sidebar Firefox Extension - Privileged Code Injection (Nick Freeman
)