eyeOS Image File Handling HTML Injection Vulnerability
BID:47629
Info
eyeOS Image File Handling HTML Injection Vulnerability
| Bugtraq ID: | 47629 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2011 12:00AM |
| Updated: | May 12 2011 02:42PM |
| Credit: | Alberto Ortega |
| Vulnerable: |
eyeOS eyeOS 1.9.0.2 |
| Not Vulnerable: |
eyeOS eyeOS 1.9.0.3 |
Discussion
eyeOS Image File Handling HTML Injection Vulnerability
eyeOS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input passed through image content before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to eyeOS 1.9.0.3 are vulnerable.
eyeOS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input passed through image content before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to eyeOS 1.9.0.3 are vulnerable.
Exploit / POC
eyeOS Image File Handling HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Solution / Fix
eyeOS Image File Handling HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
eyeOS Image File Handling HTML Injection Vulnerability
References:
References:
- Security release: eyeos 1.9.0.3 (eyeOS)
- Vendor Homepage (eyeOS)