SemanticScuttle Prior to 0.94.1 Multiple Unspecified Cross Site Scripting Vulnerabilities
BID:37034
Info
SemanticScuttle Prior to 0.94.1 Multiple Unspecified Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 37034 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2009 12:00AM |
| Updated: | Nov 16 2009 07:36PM |
| Credit: | SemanticScuttle |
| Vulnerable: |
SemanticScuttle SemanticScuttle 0.94 SemanticScuttle SemanticScuttle 0.90 SemanticScuttle SemanticScuttle 0.89 |
| Not Vulnerable: |
SemanticScuttle SemanticScuttle 0.94.1 |
Discussion
SemanticScuttle Prior to 0.94.1 Multiple Unspecified Cross Site Scripting Vulnerabilities
SemanticScuttle is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Very few details are available. We will update this BID as more information emerges.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Versions prior to SemanticScuttle 0.94.1 are vulnerable.
SemanticScuttle is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Very few details are available. We will update this BID as more information emerges.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Versions prior to SemanticScuttle 0.94.1 are vulnerable.
Exploit / POC
SemanticScuttle Prior to 0.94.1 Multiple Unspecified Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
SemanticScuttle Prior to 0.94.1 Multiple Unspecified Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
SemanticScuttle Prior to 0.94.1 Multiple Unspecified Cross Site Scripting Vulnerabilities
References:
References:
- [semanticscuttle] View of /branches/0.94.1/ChangeLog (SemanticScuttle)
- SemanticScuttle Project Page (SemanticScuttle)