ScribeFire 'img' tag HTML Injection Vulnerability
BID:36105
Info
ScribeFire 'img' tag HTML Injection Vulnerability
| Bugtraq ID: | 36105 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2009 12:00AM |
| Updated: | Aug 24 2009 09:03PM |
| Credit: | Nick Freeman |
| Vulnerable: |
ScribeFire ScribeFire 3.4.1 |
| Not Vulnerable: |
ScribeFire ScribeFire 3.4.2 |
Discussion
ScribeFire 'img' tag HTML Injection Vulnerability
ScribeFire is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Arbitrary script code supplied by the attacker would run with elevated privileges since it is rendered in with 'chrome' privileges.
This issue affects versions prior to ScribeFire 3.4.2.
ScribeFire is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Arbitrary script code supplied by the attacker would run with elevated privileges since it is rendered in with 'chrome' privileges.
This issue affects versions prior to ScribeFire 3.4.2.
Exploit / POC
ScribeFire 'img' tag HTML Injection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious RSS feed.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious RSS feed.
Solution / Fix
ScribeFire 'img' tag HTML Injection Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
ScribeFire 'img' tag HTML Injection Vulnerability
References:
References:
- ScribeFire (Mozilla Firefox Extension) �?? Code Injection Vulnerability (Security-Assessment.com)
- ScribeFire Homepage (ScribeFire)
- Version 3.4.2 �?? July 19, 2009 �?? 442 KB (ScribeFire)
- ScribeFire Firefox Extension - Privileged Code Injection (Nick Freeman
)