Flock RSS Feed Cross Domain Scripting Vulnerability
BID:43225
Info
Flock RSS Feed Cross Domain Scripting Vulnerability
| Bugtraq ID: | 43225 |
| Class: | Design Error |
| CVE: |
CVE-2010-3262 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2010 12:00AM |
| Updated: | Sep 09 2010 12:00AM |
| Credit: | Lostmon Lords |
| Vulnerable: |
Flock Flock 3.0.0.4094 Flock Flock 3.0.0 |
| Not Vulnerable: |
Flock Flock 3.0.0.4114 |
Discussion
Flock RSS Feed Cross Domain Scripting Vulnerability
Flock is prone to a cross-domain scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to bypass the same-origin protection and obtain potentially sensitive information. Other attacks are also possible.
Flock 3 versions prior to 3.0.0.4114 are vulnerable.
Flock is prone to a cross-domain scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to bypass the same-origin protection and obtain potentially sensitive information. Other attacks are also possible.
Flock 3 versions prior to 3.0.0.4114 are vulnerable.
Exploit / POC
Flock RSS Feed Cross Domain Scripting Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Flock RSS Feed Cross Domain Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Flock RSS Feed Cross Domain Scripting Vulnerability
References:
References: