CIDWeb Multiple Cross Site Scripting Vulnerabilities
BID:48362
Info
CIDWeb Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 48362 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2011 12:00AM |
| Updated: | Jun 21 2011 12:00AM |
| Credit: | Hugo Vázquez Carames |
| Vulnerable: |
Cidway CIDWeb 2.3.0.8 Cidway CIDWeb 1.0.0.0 |
| Not Vulnerable: |
Cidway CIDWeb 2.3.0.9 |
Discussion
CIDWeb Multiple Cross Site Scripting Vulnerabilities
CIDWeb is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
CIDWeb 1.0.0.0 and 2.3.0.8 are vulnerable; other versions may also be affected.
CIDWeb is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
CIDWeb 1.0.0.0 and 2.3.0.8 are vulnerable; other versions may also be affected.
Exploit / POC
CIDWeb Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
CIDWeb Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.