Croogo CMS Contact Module Multiple Cross Site Scripting Vulnerabilities
BID:38593
Info
Croogo CMS Contact Module Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 38593 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2010 12:00AM |
| Updated: | Mar 08 2010 12:00AM |
| Credit: | Paulino Calderon of webvuln |
| Vulnerable: |
Croogo Croogo CMS 1.2 |
| Not Vulnerable: |
Croogo Croogo CMS 1.2.1 |
Discussion
Croogo CMS Contact Module Multiple Cross Site Scripting Vulnerabilities
The Contact module for Croogo CMS is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Croogo CMS 1.2.1 are vulnerable.
The Contact module for Croogo CMS is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Croogo CMS 1.2.1 are vulnerable.
Exploit / POC
Croogo CMS Contact Module Multiple Cross Site Scripting Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Croogo CMS Contact Module Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Croogo CMS Contact Module Multiple Cross Site Scripting Vulnerabilities
References:
References: