XOOPS Multiple Cross Site Scripting Vulnerabilities
BID:46916
Info
XOOPS Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 46916 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2011 12:00AM |
| Updated: | Mar 18 2011 12:00AM |
| Credit: | Aung Khant of the YGN Ethical Hacker Group |
| Vulnerable: |
Xoops Xoops 2.5 Xoops Xoops 2.4.3 Xoops Xoops 2.4.2 Xoops Xoops 2.4.1 Xoops Xoops 2.4 Xoops Xoops 2.3.3 Xoops Xoops 2.3.2 b Xoops Xoops 2.3.2 Xoops Xoops 2.2.5 Xoops Xoops 2.2.3 RC1 Xoops Xoops 2.2.3 Xoops Xoops 2.2.1 Xoops Xoops 2.0.18 .1 Xoops Xoops 2.0.18 Xoops Xoops 2.0.17 1 Xoops Xoops 2.0.15 Xoops Xoops 2.0.14 Xoops Xoops 2.0.14 Xoops Xoops 2.0.13 .2 Xoops Xoops 2.0.13 .1 Xoops Xoops 2.0.12 a Xoops Xoops 2.0.12 Xoops Xoops 2.0.11 Xoops Xoops 2.0.10 Xoops Xoops 2.0.9 .3 Xoops Xoops 2.0.9 .2 Xoops Xoops 2.0.5 .2 Xoops Xoops 2.0.5 .1 Xoops Xoops 2.0.5 Xoops Xoops 2.0.3 Xoops Xoops 2.0.2 Xoops Xoops 2.0.1 Xoops Xoops 2.0 Xoops Xoops 2.3 Xoops Xoops 2.0.16 core |
| Not Vulnerable: |
Xoops Xoops 2.5.1 |
Discussion
XOOPS Multiple Cross Site Scripting Vulnerabilities
XOOPS is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
XOOPS 2.5.0 is vulnerable; other versions may also be affected.
XOOPS is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
XOOPS 2.5.0 is vulnerable; other versions may also be affected.
Exploit / POC
XOOPS Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The follow example URIs and data are available:
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The follow example URIs and data are available:
Solution / Fix
XOOPS Multiple Cross Site Scripting Vulnerabilities
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
XOOPS Multiple Cross Site Scripting Vulnerabilities
References:
References:
- XOOPS Homepage (XOOPS)
- [[email protected]: XOOPS 2.5.0 <= Cross Site Scripting Vulnerability] (YGN Ethical Hacker Group
)