Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
BID:47967
Info
Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
| Bugtraq ID: | 47967 |
| Class: | Unknown |
| CVE: |
CVE-2011-1952 CVE-2011-1953 |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2011 12:00AM |
| Updated: | Jun 01 2011 07:40PM |
| Credit: | Javier Bassi |
| Vulnerable: |
Post Revolution PostRev 0.8.0c |
| Not Vulnerable: |
Post Revolution PostRev 0.8.0c-2 |
Discussion
Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
Post Revolution is prone to multiple html-injection vulnerabilities and a denial-of-service vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Post Revolution PostRev versions prior to 0.8.0c-2 are vulnerable.
Post Revolution is prone to multiple html-injection vulnerabilities and a denial-of-service vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Post Revolution PostRev versions prior to 0.8.0c-2 are vulnerable.
Exploit / POC
Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
An attacker can exploit these issues via a browser.
An attacker can exploit these issues via a browser.
Solution / Fix
Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
References:
References:
- Post Revolution 0.8.0c Multiple vulnerabilities (Javier Bassi)
- Post Revolution Homepage (Post Revolution)
- Post Revolution Security Update (Post Revolution)