Actinic Catalog Cross Site Scripting Vulnerability
BID:4042
Info
Actinic Catalog Cross Site Scripting Vulnerability
| Bugtraq ID: | 4042 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2002 12:00AM |
| Updated: | Jul 20 2006 09:02PM |
| Credit: | Discovered by frog-m@n ([email protected]). |
| Vulnerable: |
Actinic Catalog 4.7 |
| Not Vulnerable: |
Actinic Catalog 7.0.6 |
Discussion
Actinic Catalog Cross Site Scripting Vulnerability
Actinic Catalog is an application designed for e-commerce websites and will run on most Windows and UNIX systems.
Actinic Catalog fails to sufficiently filter HTML tags, including script code, from URL parameters. An attacker can create a malicious link containing arbitrary script code. When a legitimate user browses the malicious link, the script code will run in the user's browser in the context of the website running Actinic Catalog.
Actinic Catalog is an application designed for e-commerce websites and will run on most Windows and UNIX systems.
Actinic Catalog fails to sufficiently filter HTML tags, including script code, from URL parameters. An attacker can create a malicious link containing arbitrary script code. When a legitimate user browses the malicious link, the script code will run in the user's browser in the context of the website running Actinic Catalog.
Exploit / POC
Actinic Catalog Cross Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Actinic Catalog Cross Site Scripting Vulnerability
Solution:
The vendor has released version 7.0.6 to address this issue; please contact the vendor for updates.
Solution:
The vendor has released version 7.0.6 to address this issue; please contact the vendor for updates.
References
Actinic Catalog Cross Site Scripting Vulnerability
References:
References:
- Actinic Homepage (Actinic)
- Failles dans le service d'e-commerce Actinic (frog-m@n ([email protected]))