LXR Cross Referencer Multiple Cross Site Scripting Vulnerabilities
BID:37612
Info
LXR Cross Referencer Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 37612 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4497 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2010 12:00AM |
| Updated: | Aug 17 2010 10:34PM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Cross Referencer LXR 0.9.6 Cross Referencer LXR 0.9.5 |
| Not Vulnerable: | |
Discussion
LXR Cross Referencer Multiple Cross Site Scripting Vulnerabilities
LXR Cross Referencer is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
LXR Cross Referencer 0.9.5 and 0.9.6 are affected; other versions may also be vulnerable.
LXR Cross Referencer is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
LXR Cross Referencer 0.9.5 and 0.9.6 are affected; other versions may also be vulnerable.
Exploit / POC
LXR Cross Referencer Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com/lxr/ident?i=<script>alert('XSS')</script>
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com/lxr/ident?i=<script>alert('XSS')</script>
Solution / Fix
LXR Cross Referencer Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 hppa
Debian Linux 5.0 ia-64
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 5.0 armel
Debian Linux 5.0
Debian Linux 5.0 amd64
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 hppa
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 ia-64
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 m68k
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 arm
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 armel
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 amd64
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 alpha
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 ia-32
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 mips
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 s/390
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 mipsel
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 powerpc
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
Debian Linux 5.0 sparc
-
Debian lxr-cvs_0.9.5+cvs20071020-1+lenny1_all.deb
http://security.debian.org/pool/updates/main/l/lxr-cvs/lxr-cvs_0.9.5+c vs20071020-1+lenny1_all.deb
References
LXR Cross Referencer Multiple Cross Site Scripting Vulnerabilities
References:
References:
- [Lxr-dev] [ lxr-Bugs-2926043 ] Cross-Site Scripting bugs in LXR (Dan Rosenberg)
- LXR Homepage (Cross Referencer)