Joomla! sh404SEF Component URI Cross-Site Scripting Vulnerability
BID:38191
Info
Joomla! sh404SEF Component URI Cross-Site Scripting Vulnerability
| Bugtraq ID: | 38191 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2009 12:00AM |
| Updated: | Jun 08 2009 12:00AM |
| Credit: | Jeff Channell |
| Vulnerable: |
Yannick Gaultier sh404SEF 0 |
| Not Vulnerable: |
Yannick Gaultier sh404SEF 1.0.20 Beta Build 23 |
Discussion
Joomla! sh404SEF Component URI Cross-Site Scripting Vulnerability
The sh404SEF component for Joomla! is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to sh404SEF 1.0.20 Beta Build 237 are vulnerable.
The sh404SEF component for Joomla! is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to sh404SEF 1.0.20 Beta Build 237 are vulnerable.
Exploit / POC
Joomla! sh404SEF Component URI Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Joomla! sh404SEF Component URI Cross-Site Scripting Vulnerability
Solution:
Updates are available to address this issue. Please see the references for more information.
Solution:
Updates are available to address this issue. Please see the references for more information.
References
Joomla! sh404SEF Component URI Cross-Site Scripting Vulnerability
References:
References:
- Joomla! Homepage (Joomla!)
- sh404SEF Extension Homepage (Yannick Gaultier)