JoomlaTune JComments Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability
BID:40230
Info
JoomlaTune JComments Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 40230 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2010 12:00AM |
| Updated: | May 18 2010 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
JoomlaTune JComments 2.1 |
| Not Vulnerable: |
JoomlaTune JComments 2.2 |
Discussion
JoomlaTune JComments Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability
The JComments component for Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to JComments 2.2 are vulnerable.
The JComments component for Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to JComments 2.2 are vulnerable.
Exploit / POC
JoomlaTune JComments Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following exploit is available:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following exploit is available:
Solution / Fix
JoomlaTune JComments Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability
Solution:
Updates are available; please see the references for more information.
JoomlaTune JComments 2.1
Solution:
Updates are available; please see the references for more information.
JoomlaTune JComments 2.1
-
JoomlaTune com_jcomments_v2.2.0.0.zip
http://www.joomlatune.com/downloads/jcomments/com_jcomments_v2.2.0.0.z ip
References
JoomlaTune JComments Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability
References:
References:
- JComments 2.2 Release Notes (JoomlaTune)
- JComments Homepage (JoomlaTune)
- Joomla! Homepage (Joomla )
- XSS vulnerability in JComments, Joomla (High-Tech Bridge SA)
- XSS vulnerability in JComments, Joomla ([email protected])