tDiary TrackBack Transmission Plugin Cross-Site Scripting Vulnerability
BID:38413
Info
tDiary TrackBack Transmission Plugin Cross-Site Scripting Vulnerability
| Bugtraq ID: | 38413 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0726 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Yubisekyua project, VEX Inc. |
| Vulnerable: |
tDiary tDiary 2.1.2 tDiary tDiary 2.1.1 tDiary tDiary 2.0.4 tDiary tDiary 2.0.3 tDiary tDiary 2.0.2 tDiary tDiary 2.1.4.20061126 tDiary tDiary 2.1.4.20061115 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
tDiary tDiary 2.2.3 |
Discussion
tDiary TrackBack Transmission Plugin Cross-Site Scripting Vulnerability
tDiary is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to tDiary 2.2.3 are vulnerable.
tDiary is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to tDiary 2.2.3 are vulnerable.
Exploit / POC
tDiary TrackBack Transmission Plugin Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
tDiary TrackBack Transmission Plugin Cross-Site Scripting Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
tDiary TrackBack Transmission Plugin Cross-Site Scripting Vulnerability
References:
References:
- JVN#73331060 (JVN)
- tDiary 2.2.3 Release Notes (tDiary)
- Vendor Homepage (tDiary)