Joomla! Jobline Component 'Itemid' Parameter Cross Site Scripting Vulnerability
BID:40996
Info
Joomla! Jobline Component 'Itemid' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 40996 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2010 12:00AM |
| Updated: | Jun 21 2010 12:00AM |
| Credit: | Sid3^effects |
| Vulnerable: |
Olle Johansson Jobline 1.1.3.1 |
| Not Vulnerable: |
Olle Johansson Jobline 1.1.3.2 |
Discussion
Joomla! Jobline Component 'Itemid' Parameter Cross Site Scripting Vulnerability
The Jobline component for Joomla! is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this vulnerability could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Jobline 1.1.3.1 is vulnerable; prior versions may also be affected.
The Jobline component for Joomla! is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this vulnerability could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Jobline 1.1.3.1 is vulnerable; prior versions may also be affected.
Exploit / POC
Joomla! Jobline Component 'Itemid' Parameter Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Joomla! Jobline Component 'Itemid' Parameter Cross Site Scripting Vulnerability
Solution:
The vendor released an update. Please see the references for more information.
Solution:
The vendor released an update. Please see the references for more information.
References
Joomla! Jobline Component 'Itemid' Parameter Cross Site Scripting Vulnerability
References:
References:
- Jobline Homepage (Olle Johansson)
- Joomla! Homepage (Joomla!)