Multiple Things CGI Products Unspecified Cross Site Scripting Vulnerability
BID:46638
Info
Multiple Things CGI Products Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 46638 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0455 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2011 12:00AM |
| Updated: | Mar 02 2011 12:00AM |
| Credit: | Yuji Tounai, bogus.jp |
| Vulnerable: |
Things CGI BBS Thread 2.0.2 Things CGI BBS 2.0.2 |
| Not Vulnerable: |
Things CGI BBS Thread 2.0.3 Things CGI BBS 2.0.3 |
Discussion
Multiple Things CGI Products Unspecified Cross Site Scripting Vulnerability
Multiple Things CGI products are prone to a cross-site scripting vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to BBS 2.0.3 and BBS Thread 2.0.3 are vulnerable.
Multiple Things CGI products are prone to a cross-site scripting vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to BBS 2.0.3 and BBS Thread 2.0.3 are vulnerable.
Exploit / POC
Multiple Things CGI Products Unspecified Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Multiple Things CGI Products Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Multiple Things CGI Products Unspecified Cross Site Scripting Vulnerability
References:
References:
- BBS Homepage (Things CGI)
- Multiple Things CGI products vulnerable to cross-site scripting (JPCERT/CC and IPA)