DotNetNuke User Messaging Module HTML Injection Vulnerability
BID:40297
Info
DotNetNuke User Messaging Module HTML Injection Vulnerability
| Bugtraq ID: | 40297 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2010 12:00AM |
| Updated: | May 19 2010 12:00AM |
| Credit: | Chris Wood |
| Vulnerable: |
DotNetNuke DotNetNuke 5.4.1 DotNetNuke DotNetNuke 5.4 DotNetNuke DotNetNuke 5.3.1 DotNetNuke DotNetNuke 5.3 |
| Not Vulnerable: |
DotNetNuke DotNetNuke 5.4.2 |
Discussion
DotNetNuke User Messaging Module HTML Injection Vulnerability
DotNetNuke is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
DotNetNuke 5.3.0 through 5.4.1 are vulnerable.
DotNetNuke is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
DotNetNuke 5.3.0 through 5.4.1 are vulnerable.
Exploit / POC
DotNetNuke User Messaging Module HTML Injection Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
DotNetNuke User Messaging Module HTML Injection Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
DotNetNuke User Messaging Module HTML Injection Vulnerability
References:
References:
- HTML/Script Code Injection Vulnerability in User messaging (DotNetNuke)
- DotNetNuke Homepage (DotNetNuke)