FeedDemon 'Feed Preview' Arbitrary Script Injection Vulnerability
BID:53858
Info
FeedDemon 'Feed Preview' Arbitrary Script Injection Vulnerability
| Bugtraq ID: | 53858 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2634 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2012 12:00AM |
| Updated: | Jun 07 2012 12:00AM |
| Credit: | JVN credits Daiki Fukumori, Cyber Defense Institute |
| Vulnerable: |
NewsGator FeedDemon 3.1.0.9 |
| Not Vulnerable: |
NewsGator FeedDemon 4.1.0.0 |
Discussion
FeedDemon 'Feed Preview' Arbitrary Script Injection Vulnerability
FeedDemon is prone to an arbitrary script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code within the context of the application.
Versions prior to FeedDemon 4.1.0.0 are vulnerable.
FeedDemon is prone to an arbitrary script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code within the context of the application.
Versions prior to FeedDemon 4.1.0.0 are vulnerable.
Exploit / POC
FeedDemon 'Feed Preview' Arbitrary Script Injection Vulnerability
To launch an attack, an attacker must entice a victim into viewing a malicious website.
To launch an attack, an attacker must entice a victim into viewing a malicious website.
Solution / Fix
FeedDemon 'Feed Preview' Arbitrary Script Injection Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
FeedDemon 'Feed Preview' Arbitrary Script Injection Vulnerability
References:
References:
- FeedDemon Homepage (NewsGator)
- FeedDemon vulnerable to arbitrary script execution (JVNDB)
- FeedDemon vulnerable to arbitrary script execution (Daiki Fukumori)