Multiple Products Regular Subscriber HTML Injection Vulnerability
BID:49765
Info
Multiple Products Regular Subscriber HTML Injection Vulnerability
| Bugtraq ID: | 49765 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2011 12:00AM |
| Updated: | Sep 26 2011 12:00AM |
| Credit: | knull |
| Vulnerable: |
WPMU DEV Blogs Mu 1.2.6 WordPress WordPress 3.1.4 WordPress WordPress 3.1.3 WordPress WordPress 3.1.2 WordPress WordPress 3.1.1 WordPress WordPress 3.1.3 WordPress WordPress 3.1 BuddyPress BuddyPress 1.2.10 |
| Not Vulnerable: |
WPMU DEV Blogs Mu 1.2.7 BuddyPress BuddyPress 1.5 |
Discussion
Multiple Products Regular Subscriber HTML Injection Vulnerability
Multiple products are prone to an HTML-injection vulnerability because they fail to sufficiently sanitize user-supplied input.
An attacker could exploit this vulnerability to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected websites. This may allow the attacker to steal cookie-based authentication credentials or control how the websites are rendered to the user. Other attacks are also possible.
The following products are affected:
WordPress 3.1.4
BuddyPress 1.2.10
Blogs MU 1.2.6
Multiple products are prone to an HTML-injection vulnerability because they fail to sufficiently sanitize user-supplied input.
An attacker could exploit this vulnerability to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected websites. This may allow the attacker to steal cookie-based authentication credentials or control how the websites are rendered to the user. Other attacks are also possible.
The following products are affected:
WordPress 3.1.4
BuddyPress 1.2.10
Blogs MU 1.2.6
Exploit / POC
Multiple Products Regular Subscriber HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Multiple Products Regular Subscriber HTML Injection Vulnerability
Solution:
Updates are available for Blog MU and BuddyPress. Please see the references for details.
Currently, we are not aware of any vendor-supplied patches for WordPress. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Updates are available for Blog MU and BuddyPress. Please see the references for details.
Currently, we are not aware of any vendor-supplied patches for WordPress. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Products Regular Subscriber HTML Injection Vulnerability
References:
References:
- WordPress + Buddypress + Blogs Mu Theme Cross Site Scripting (knull)
- WordPress Homepage (WordPress)