ConPresso CMS 'mod_search/index.php' Multiple Cross Site Scripting Vulnerabilities
BID:41690
Info
ConPresso CMS 'mod_search/index.php' Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 41690 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2010 12:00AM |
| Updated: | Jul 13 2010 12:00AM |
| Credit: | David Vieira-Kurz |
| Vulnerable: |
Bartels Schone ConPresso 4.1.1 |
| Not Vulnerable: |
Bartels Schone ConPresso 4.1.2 |
Discussion
ConPresso CMS 'mod_search/index.php' Multiple Cross Site Scripting Vulnerabilities
ConPresso CMS is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ConPresso CMS 4.1.1 is vulnerable; prior versions may also be affected.
ConPresso CMS is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ConPresso CMS 4.1.1 is vulnerable; prior versions may also be affected.
Exploit / POC
ConPresso CMS 'mod_search/index.php' Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user into following a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user into following a malicious URI.
Solution / Fix
ConPresso CMS 'mod_search/index.php' Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
ConPresso CMS 'mod_search/index.php' Multiple Cross Site Scripting Vulnerabilities
References:
References:
- ConPresso CMS Homepage (Bartels Schone)