Mako 'cgi.escape()' Cross-Site Scripting Vulnerability
BID:41278
Info
Mako 'cgi.escape()' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 41278 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2480 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2010 12:00AM |
| Updated: | Apr 13 2015 09:34PM |
| Credit: | Craig Younkins |
| Vulnerable: |
Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 amd64 S.u.S.E. openSUSE 11.3 S.u.S.E. openSUSE 11.2 Mako Mako 0.3.3 |
| Not Vulnerable: |
Mako Mako 0.3.4 |
Discussion
Mako 'cgi.escape()' Cross-Site Scripting Vulnerability
Mako is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects Mako versions prior to 0.3.4.
Mako is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects Mako versions prior to 0.3.4.
Exploit / POC
Mako 'cgi.escape()' Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Mako 'cgi.escape()' Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 10.04 amd64
Ubuntu Ubuntu Linux 10.04 powerpc
Ubuntu Ubuntu Linux 10.04 sparc
Ubuntu Ubuntu Linux 10.04 i386
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 10.04 amd64
-
Ubuntu python-mako_0.2.5-2ubuntu1.3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/mako/python-mako_0.2.5-2 ubuntu1.3_all.deb
Ubuntu Ubuntu Linux 10.04 powerpc
-
Ubuntu python-mako_0.2.5-2ubuntu1.3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/mako/python-mako_0.2.5-2 ubuntu1.3_all.deb
Ubuntu Ubuntu Linux 10.04 sparc
-
Ubuntu python-mako_0.2.5-2ubuntu1.3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/mako/python-mako_0.2.5-2 ubuntu1.3_all.deb
Ubuntu Ubuntu Linux 10.04 i386
-
Ubuntu python-mako_0.2.5-2ubuntu1.3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/mako/python-mako_0.2.5-2 ubuntu1.3_all.deb
References
Mako 'cgi.escape()' Cross-Site Scripting Vulnerability
References:
References:
- Issue9061: cgi.escape Can Lead To XSS Vulnerabilities (Python Software Foundation)
- Mako 0.3.4 Changes (Mako)
- Mako Homepage (Mako)