Sourcefabric Campsite Multiple Cross Site Scripting Vulnerabilities
BID:42107
Info
Sourcefabric Campsite Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 42107 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2010 12:00AM |
| Updated: | Aug 20 2010 04:53PM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Sourcefabric Campsite Multiple Cross Site Scripting Vulnerabilities
Sourcefabric Campsite is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Sourcefabric Campsite 3.3.6 is vulnerable; prior versions may also be affected.
Sourcefabric Campsite is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Sourcefabric Campsite 3.3.6 is vulnerable; prior versions may also be affected.
Solution / Fix
Sourcefabric Campsite Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Sourcefabric Campsite Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Campsite 3.4.1 Security Update Released (Sourcefabric)
- Campsite Homepage (Sourcefabric)
- Campsite Project Page (SourceForge)
- Release Notes - Campsite - Version 3.4.1 - HTML format (Sourcefabric)
- XSS vulnerability in Campsite ([email protected])
- XSS vulnerability in Campsite ([email protected])