Ninja Blog Cross Site Scripting and Remote File Include Vulnerabilities
BID:40584
Info
Ninja Blog Cross Site Scripting and Remote File Include Vulnerabilities
| Bugtraq ID: | 40584 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2010 12:00AM |
| Updated: | Jan 04 2010 12:00AM |
| Credit: | indoushka |
| Vulnerable: |
Ninja Designs Ninja Blog 4.8 |
| Not Vulnerable: | |
Discussion
Ninja Blog Cross Site Scripting and Remote File Include Vulnerabilities
Ninja Blog is prone to a cross-site scripting vulnerability and a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or of the webserver process. This may allow the attacker to steal cookie-based authentication credentials or obtain potentially sensitive information; other attacks are also possible.
Ninja Blog 4.8 is vulnerable; other versions may also be affected.
Ninja Blog is prone to a cross-site scripting vulnerability and a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or of the webserver process. This may allow the attacker to steal cookie-based authentication credentials or obtain potentially sensitive information; other attacks are also possible.
Ninja Blog 4.8 is vulnerable; other versions may also be affected.
Exploit / POC
Ninja Blog Cross Site Scripting and Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser. To exploit the cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
An attacker can exploit these issues via a browser. To exploit the cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
Solution / Fix
Ninja Blog Cross Site Scripting and Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ninja Blog Cross Site Scripting and Remote File Include Vulnerabilities
References:
References:
- Ninja Blog Download (Ninja Designs)
- Ninja Designs Homepage (Ninja Designs)