Concrete 'rcID' Parameter Cross Site Scripting Vulnerability
BID:49276
Info
Concrete 'rcID' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 49276 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2011 12:00AM |
| Updated: | Aug 22 2011 12:00AM |
| Credit: | Aung Khant |
| Vulnerable: |
concrete5 concrete5 5.4.1 1 |
| Not Vulnerable: |
concrete5 concrete5 5.4.2 |
Discussion
Concrete 'rcID' Parameter Cross Site Scripting Vulnerability
Concrete is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Concrete 5.4.1.1 is vulnerable; other versions may also be affected.
Concrete is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Concrete 5.4.1.1 is vulnerable; other versions may also be affected.
Exploit / POC
Concrete 'rcID' Parameter Cross Site Scripting Vulnerability
To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following proof-of-concept URI is available:
To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following proof-of-concept URI is available:
Solution / Fix
Concrete 'rcID' Parameter Cross Site Scripting Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Concrete 'rcID' Parameter Cross Site Scripting Vulnerability
References:
References:
- concrete5 Homepage (concrete5)