Enano CMS Unspecified Cross Site Scripting Vulnerability
BID:47080
Info
Enano CMS Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 47080 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 29 2011 12:00AM |
| Updated: | Mar 29 2011 12:00AM |
| Credit: | Mesut Timur |
| Vulnerable: |
Enano Enano CMS 1.0.6 Enano Enano CMS 1.1.7 Enano Enano CMS 1.1.6pl2 Enano Enano CMS 1.0.6pl1 |
| Not Vulnerable: |
Enano Enano CMS 1.1.7pl1 Enano Enano CMS 1.0.6pl2 |
Discussion
Enano CMS Unspecified Cross Site Scripting Vulnerability
Enano CMS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Enano CMS 1.1.7 and 1.0.6pl1 are affected.
Enano CMS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Enano CMS 1.1.7 and 1.0.6pl1 are affected.
Exploit / POC
Enano CMS Unspecified Cross Site Scripting Vulnerability
To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Enano CMS Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Enano CMS Unspecified Cross Site Scripting Vulnerability
References:
References:
- Enano 1.0.6pl2 and 1.1.7pl1 released (Enano)
- Enano CMS Homepage (Enano)
- XSS vulnerability in EnanoCms (Mavituna Security)