Achievo Scheduler Category HTML Injection Vulnerability
BID:37220
Info
Achievo Scheduler Category HTML Injection Vulnerability
| Bugtraq ID: | 37220 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2009 12:00AM |
| Updated: | Dec 10 2009 12:44AM |
| Credit: | Nahuel Grisolia from CYBSEC S.A |
| Vulnerable: |
Achievo Achievo 1.4.2 Achievo Achievo 1.4 Achievo Achievo 1.3.4 Achievo Achievo 1.3.2 Achievo Achievo 1.2.1 Achievo Achievo 1.1 Achievo Achievo 1.2 |
| Not Vulnerable: |
Achievo Achievo 1.4.3 |
Discussion
Achievo Scheduler Category HTML Injection Vulnerability
Achievo is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Achievo 1.4.3 are vulnerable.
Achievo is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Achievo 1.4.3 are vulnerable.
Exploit / POC
Achievo Scheduler Category HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Achievo Scheduler Category HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Achievo Scheduler Category HTML Injection Vulnerability
References:
References:
- Achievo Homepage (Achievo)
- Permanent Cross-Site Scripting (XSS) in Achievo 1.4.2 (PDF) (CYBSEC S.A)