Geeklog HTML Attribute Cross Site Scripting Vulnerability
BID:5270
Info
Geeklog HTML Attribute Cross Site Scripting Vulnerability
| Bugtraq ID: | 5270 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2002 12:00AM |
| Updated: | Jul 19 2002 12:00AM |
| Credit: | Discovery credited to Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
Geeklog Geeklog 1.3.5 sr1 Geeklog Geeklog 1.3.5 |
| Not Vulnerable: |
Geeklog Geeklog 1.3.5 sr2 |
Discussion
Geeklog HTML Attribute Cross Site Scripting Vulnerability
A cross site scripting vulnerability has been reported for Geeklog. Reportedly, Geeklog does not properly sanitize user supplied input before being included when posting comments or writing stories.
Geeklog makes efforts to sanitize some malicious user supplied input by stripping out HTML elements that are used for scripting. However, Geeklog does not properly remove HTML attributes that are used for the same purpose.
It is possible for an attacker to include malicious HTML code using the HTML attributes. As an example, if an attacker were to supply malicious HTML code as part of an onMouseOver JavaScript event, the malicious code would not be properly sanitized.
A cross site scripting vulnerability has been reported for Geeklog. Reportedly, Geeklog does not properly sanitize user supplied input before being included when posting comments or writing stories.
Geeklog makes efforts to sanitize some malicious user supplied input by stripping out HTML elements that are used for scripting. However, Geeklog does not properly remove HTML attributes that are used for the same purpose.
It is possible for an attacker to include malicious HTML code using the HTML attributes. As an example, if an attacker were to supply malicious HTML code as part of an onMouseOver JavaScript event, the malicious code would not be properly sanitized.
Exploit / POC
Geeklog HTML Attribute Cross Site Scripting Vulnerability
The following proof of concept was provided by Ulf Harnhammar <[email protected]>:
<b onMouseOver="self.location.href='http://localhost/geeklog/'">
The following proof of concept was provided by Ulf Harnhammar <[email protected]>:
<b onMouseOver="self.location.href='http://localhost/geeklog/'">
Solution / Fix
Geeklog HTML Attribute Cross Site Scripting Vulnerability
Solution:
The vendor has released a newer version of Geeklog to address this issue:
Geeklog Geeklog 1.3.5
Geeklog Geeklog 1.3.5 sr1
Solution:
The vendor has released a newer version of Geeklog to address this issue:
Geeklog Geeklog 1.3.5
-
Geeklog geeklog-1.3.5sr2.tar.gz
http://prdownloads.sourceforge.net/geeklog/geeklog-1.3.5sr2.tar.gz
Geeklog Geeklog 1.3.5 sr1
-
Geeklog geeklog-1.3.5sr2.tar.gz
http://prdownloads.sourceforge.net/geeklog/geeklog-1.3.5sr2.tar.gz