JumpBox for the Foswiki Wiki System Multiple Cross Site Scripting Vulnerabilities
BID:41896
Info
JumpBox for the Foswiki Wiki System Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 41896 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4853 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2009 12:00AM |
| Updated: | Nov 16 2009 12:00AM |
| Credit: | Vulnerabilities reported by the vendor |
| Vulnerable: |
JumpBox JumpBox for the Foswiki Wiki System 1.1.1 |
| Not Vulnerable: |
JumpBox JumpBox for the Foswiki Wiki System 1.1.2 |
Discussion
JumpBox for the Foswiki Wiki System Multiple Cross Site Scripting Vulnerabilities
JumpBox for the Foswiki Wiki System is prone to multiple unspecified cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
JumpBox for the Foswiki Wiki System 1.1.1 and prior are vulnerable.
JumpBox for the Foswiki Wiki System is prone to multiple unspecified cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
JumpBox for the Foswiki Wiki System 1.1.1 and prior are vulnerable.
Exploit / POC
JumpBox for the Foswiki Wiki System Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
JumpBox for the Foswiki Wiki System Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly these issues have been fixed in JumpBox for the Foswiki Wiki System 1.1.2. Please see the references for more information.
Solution:
Reportedly these issues have been fixed in JumpBox for the Foswiki Wiki System 1.1.2. Please see the references for more information.
References
JumpBox for the Foswiki Wiki System Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Foswiki Homepage (Foswiki)
- JumpBox for the Foswiki Wiki System Homepage (JumpBox)