Croogo CMS 'Contact' Module HTML Injection Vulnerability
BID:38583
Info
Croogo CMS 'Contact' Module HTML Injection Vulnerability
| Bugtraq ID: | 38583 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2010 12:00AM |
| Updated: | Mar 08 2010 12:00AM |
| Credit: | Paulino Calderon |
| Vulnerable: |
Croogo Croogo CMS 1.2 |
| Not Vulnerable: |
Croogo Croogo CMS 1.2.1 |
Discussion
Croogo CMS 'Contact' Module HTML Injection Vulnerability
Croogo CMS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Croogo CMS 1.2.1 are vulnerable.
Croogo CMS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Croogo CMS 1.2.1 are vulnerable.
Exploit / POC
Croogo CMS 'Contact' Module HTML Injection Vulnerability
Attackers can exploit this issue with a web browser.
Attackers can exploit this issue with a web browser.
Solution / Fix
Croogo CMS 'Contact' Module HTML Injection Vulnerability
Solution:
Reports indicate that vendor updates are available; this has not been confirmed. Please contact the vendor for more information.
Solution:
Reports indicate that vendor updates are available; this has not been confirmed. Please contact the vendor for more information.