Zope 'standard_error_message' Cross-Site Scripting Vulnerability
BID:37765
Info
Zope 'standard_error_message' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 37765 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1104 CVE-2011-4924 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2010 12:00AM |
| Updated: | Mar 08 2012 12:30PM |
| Credit: | The Plone team |
| Vulnerable: |
Zope Zope 3.4.1 Zope Zope 3.3.3 Zope Zope 3.2.4 Zope Zope 3.1.1 Zope Zope 2.12.20 Zope Zope 2.12.3 Zope Zope 2.11.7 Zope Zope 2.11.6 Zope Zope 2.11.5 Zope Zope 2.11.4 Zope Zope 2.11.2 Zope Zope 2.10.12 Zope Zope 2.10.11 Zope Zope 2.10.10 Zope Zope 2.10.9 Zope Zope 2.10.7 Zope Zope 2.10.6 Zope Zope 2.10.5 Zope Zope 2.10.4 Zope Zope 2.10.2 Zope Zope 2.10.1 Zope Zope 2.9.12 Zope Zope 2.9.11 Zope Zope 2.9.3 Zope Zope 2.9.2 Zope Zope 2.9.1 Zope Zope 2.9 Zope Zope 2.8.12 Zope Zope 2.8.11 Zope Zope 2.8.8 Zope Zope 2.8.7 Zope Zope 2.8.6 Zope Zope 2.8.5 Zope Zope 2.8.4 Zope Zope 2.8.3 Zope Zope 2.8.2 Zope Zope 2.8.1 Zope Zope 2.7.8 Zope Zope 2.7.7 Zope Zope 2.7.6 Zope Zope 2.7.5 Zope Zope 2.7.4 Zope Zope 2.7.3 Zope Zope 2.7.2 Zope Zope 2.7.1 Zope Zope 2.7 .0 BETA4 Zope Zope 2.7 .0 BETA3 Zope Zope 2.7 .0 BETA2 Zope Zope 2.7 .0 BETA1 Zope Zope 2.6.3 Zope Zope 2.6.2 Zope Zope 2.6.1 Zope Zope 2.6 .0b1 Zope Zope 2.5.1 b1 Zope Zope 2.5.1 Zope Zope 2.5 .0 Zope Zope 2.4.4 b1 Zope Zope 2.4.3 Zope Zope 2.4.2 Zope Zope 2.4.1 Zope Zope 2.4 .0 Zope Zope 2.3.3 Zope Zope 2.3.2 Zope Zope 2.3.1 Zope Zope 2.3 .0 Zope Zope 2.2.5 Zope Zope 2.2.4 Zope Zope 2.2.3 Zope Zope 2.2.2 Zope Zope 2.2.1 Zope Zope 2.2 .0 Zope Zope 2.2 beta1 Zope Zope 2.2 Zope Zope 2.1.7 Zope Zope 2.1.1 Zope Zope 2.1 .x Zope Zope 1.10.3 Zope Zope 2.13.9 Zope Zope 2.13.8 Zope Zope 2.13.6 Zope Zope 2.13.10 Zope Zope 2.13 Zope Zope 2.12.19 Zope Zope 2.12 Zope Zope 2.11.8 RedHat Enterprise Linux Clustering 5 server Plone Plone 3.3.3 Oracle Enterprise Linux 5 |
| Not Vulnerable: |
Zope Zope 3.7.3 Zope Zope 2.12.22 Zope Zope 2.13.12 Plone Plone 3.3.4 |
Discussion
Zope 'standard_error_message' Cross-Site Scripting Vulnerability
Zope is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Note: Initial fixes did not properly address this issue. Updated vendor patches are available.
Zope is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Note: Initial fixes did not properly address this issue. Updated vendor patches are available.
Exploit / POC
Zope 'standard_error_message' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Zope 'standard_error_message' Cross-Site Scripting Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Note: Initial fixes did not properly address this issue. Updated vendor patches are available.
Solution:
The vendor has released updates. Please see the references for details.
Note: Initial fixes did not properly address this issue. Updated vendor patches are available.
References
Zope 'standard_error_message' Cross-Site Scripting Vulnerability
References:
References: