Sourcefabric Newscoop Comment HTML Injection Vulnerability
BID:46889
Info
Sourcefabric Newscoop Comment HTML Injection Vulnerability
| Bugtraq ID: | 46889 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2011 12:00AM |
| Updated: | Mar 15 2011 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Sourcefabric Newscoop 3.5.1 |
| Not Vulnerable: |
Sourcefabric Newscoop 3.5.2 |
Discussion
Sourcefabric Newscoop Comment HTML Injection Vulnerability
Sourcefabric Newscoop is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Sourcefabric Newscoop versions prior to 3.5.2 are vulnerable.
Sourcefabric Newscoop is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Sourcefabric Newscoop versions prior to 3.5.2 are vulnerable.
Solution / Fix
Sourcefabric Newscoop Comment HTML Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Sourcefabric Newscoop Comment HTML Injection Vulnerability
References:
References:
- Newscoop Homepage (Sourcefabric)
- XSS vulnerability in comments form compromises the backend (Sourcefabric)