Zyncro Multiple HTML Injection Vulnerabilities
BID:49740
Info
Zyncro Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 49740 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2011 12:00AM |
| Updated: | Sep 22 2011 12:00AM |
| Credit: | Ferran Pichel Llaquet |
| Vulnerable: |
Zyncro Zyncro 3.0.1.20 |
| Not Vulnerable: | |
Discussion
Zyncro Multiple HTML Injection Vulnerabilities
Zyncro is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Note: To exploit these issues, an attacker must have the ability to create a new group and capture the packets transferred.
An attacker could exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Zyncro 3.0.1.20 is vulnerable; other versions may also be affected.
Zyncro is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Note: To exploit these issues, an attacker must have the ability to create a new group and capture the packets transferred.
An attacker could exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Zyncro 3.0.1.20 is vulnerable; other versions may also be affected.
Exploit / POC
Zyncro Multiple HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following proof of concept is available:
Attackers can use a browser to exploit these issues.
The following proof of concept is available:
Solution / Fix
Zyncro Multiple HTML Injection Vulnerabilities
Solution:
Reports indicate the vendor has addressed these issues; this has not been confirmed. Please contact the vendor for more information.
Solution:
Reports indicate the vendor has addressed these issues; this has not been confirmed. Please contact the vendor for more information.
References
Zyncro Multiple HTML Injection Vulnerabilities
References:
References:
- [ISecAuditors Security Advisories] Multiple vulnerabilities in Zyncro social net (ISecAuditors)
- Zyncro Homepage (Zyncro )