Aditus Consulting JpGraph Multiple Cross-Site Scripting Vulnerabilities
BID:37483
Info
Aditus Consulting JpGraph Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 37483 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4422 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2009 12:00AM |
| Updated: | Dec 29 2009 08:43PM |
| Credit: | Martin Barbella |
| Vulnerable: |
MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Aditus Consulting JpGraph 3.0.6 |
| Not Vulnerable: | |
Discussion
Aditus Consulting JpGraph Multiple Cross-Site Scripting Vulnerabilities
Aditus Consulting JpGraph is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Aditus Consulting JpGraph 3.0.6 is vulnerable; other versions may also be affected.
Aditus Consulting JpGraph is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Aditus Consulting JpGraph 3.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
Aditus Consulting JpGraph Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting to victim to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting to victim to follow a malicious URI.
Solution / Fix
Aditus Consulting JpGraph Multiple Cross-Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Corporate Server 4.0
MandrakeSoft Enterprise Server 5
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva php-jpgraph-2.3.3-1.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva php-jpgraph-doc-2.3.3-1.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva php5-jpgraph-2.1.1-1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva php5-jpgraph-doc-2.1.1-1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva php-jpgraph-2.3.3-1.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva php-jpgraph-doc-2.3.3-1.1mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva php5-jpgraph-2.1.1-1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva php5-jpgraph-doc-2.1.1-1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
References
Aditus Consulting JpGraph Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- JpGraph Homepage (Aditus Consulting)
- XSS Vulnerability in JpGraph 3.0.6 (Martin Barbella
)