ikiwiki 'htmlscrubber' Plugin Remote Script Code Injection Vulnerability
BID:38844
Info
ikiwiki 'htmlscrubber' Plugin Remote Script Code Injection Vulnerability
| Bugtraq ID: | 38844 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1195 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2010 12:00AM |
| Updated: | Apr 13 2015 09:13PM |
| Credit: | The vendor credits Ivan Shmakov. |
| Vulnerable: |
ikiwiki ikiwiki 2.53.4 ikiwiki ikiwiki 3.1415926 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
ikiwiki ikiwiki 2.53.5 ikiwiki ikiwiki 3.20100312 |
Discussion
ikiwiki 'htmlscrubber' Plugin Remote Script Code Injection Vulnerability
The 'ikiwiki' program is prone to a remote script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary HTML or script code within the context of the affected application.
Versions prior to ikiwiki 3.20100312 and 2.53.5 are vulnerable.
The 'ikiwiki' program is prone to a remote script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary HTML or script code within the context of the affected application.
Versions prior to ikiwiki 3.20100312 and 2.53.5 are vulnerable.
Solution / Fix
ikiwiki 'htmlscrubber' Plugin Remote Script Code Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 hppa
Debian Linux 5.0 ia-64
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 5.0 armel
Debian Linux 5.0
Debian Linux 5.0 amd64
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 hppa
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 ia-64
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 m68k
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 arm
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 armel
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 amd64
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 alpha
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 ia-32
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 mips
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 s/390
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 mipsel
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 powerpc
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
Debian Linux 5.0 sparc
-
Debian ikiwiki_2.53.5_all.deb
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_2.53.5_ all.deb
References
ikiwiki 'htmlscrubber' Plugin Remote Script Code Injection Vulnerability
References:
References:
- ikiwiki Homepage (ikiwiki)
- ikiwiki Security Fix: javascript insertion via svg uris (ikiwiki)