Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
BID:48011
Info
Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 48011 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1077 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2011 12:00AM |
| Updated: | May 31 2011 05:01PM |
| Credit: | Riyaz Ahemed Walikar of Microland Ltd. |
| Vulnerable: |
Apache Archiva 1.3.4 Apache Archiva 1.3.3 Apache Archiva 1.3.2 Apache Archiva 1.3.1 Apache Archiva 1.3 |
| Not Vulnerable: |
Apache Archiva 1.3.5 |
Discussion
Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
Apache Archiva is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Apache Archiva 1.3.5 are vulnerable.
Apache Archiva is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Apache Archiva 1.3.5 are vulnerable.
Exploit / POC
Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
Solution / Fix
Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
Apache Archiva Multiple Cross Site Scripting and HTML Injection Vulnerabilities
References:
References:
- [SECURITY] CVE-2011-1077: Apache Archiva Multiple XSS vulnerability (Apache Archiva Team)
- Apache Archiva Homepage (Apache Software Foundation)