HTML Purifier Cross-Site Scripting and Denial of Service Vulnerabilities
BID:47053
Info
HTML Purifier Cross-Site Scripting and Denial of Service Vulnerabilities
| Bugtraq ID: | 47053 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2011 12:00AM |
| Updated: | Mar 28 2011 12:00AM |
| Credit: | Neike Taika-Tessaro and Mario Heiderich. |
| Vulnerable: |
Edward Z. Yang HTML Purifier 4.2 Edward Z. Yang HTML Purifier 4.1.1 Edward Z. Yang HTML Purifier 4.1 Edward Z. Yang HTML Purifier 4.0 |
| Not Vulnerable: |
Edward Z. Yang HTML Purifier 4.3 |
Discussion
HTML Purifier Cross-Site Scripting and Denial of Service Vulnerabilities
HTML Purifier is prone to multiple cross-site scripting vulnerabilities and a denial-of-service vulnerability because it fails to properly handle user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
HTML Purifier versions prior to 4.3.0 are vulnerable.
HTML Purifier is prone to multiple cross-site scripting vulnerabilities and a denial-of-service vulnerability because it fails to properly handle user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
HTML Purifier versions prior to 4.3.0 are vulnerable.
Exploit / POC
HTML Purifier Cross-Site Scripting and Denial of Service Vulnerabilities
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
References
HTML Purifier Cross-Site Scripting and Denial of Service Vulnerabilities
References:
References:
- HTML Purifier 4.3.0 released (Edward K. Zang)
- HTML Purifier Homepage (Edward Z. Yang)
- HTML Purifier Web Site (Edward Z. Yang)