Geeklog BBCode Tags HTML Injection Vulnerabilities
BID:50060
Info
Geeklog BBCode Tags HTML Injection Vulnerabilities
| Bugtraq ID: | 50060 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4647 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2011 12:00AM |
| Updated: | Dec 05 2011 06:27PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Geeklog Geeklog 1.8.0 |
| Not Vulnerable: |
Geeklog Geeklog 1.8.1 |
Discussion
Geeklog BBCode Tags HTML Injection Vulnerabilities
Geeklog is prone to HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Geeklog versions prior to 1.8.1 are vulnerable.
Geeklog is prone to HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Geeklog versions prior to 1.8.1 are vulnerable.
Solution / Fix
Geeklog BBCode Tags HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Geeklog BBCode Tags HTML Injection Vulnerabilities
References:
References:
- Geeklog buqtrack (Geeklog)
- Geeklog changelog (Geeklog)
- Geeklog Homepage (Geeklog)