CafeLog b2 WebLog Tool Cross Site Scripting Vulnerability
BID:5455
Info
CafeLog b2 WebLog Tool Cross Site Scripting Vulnerability
| Bugtraq ID: | 5455 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1464 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Reported by "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
Cafelog b2 2.6 pre4 |
| Not Vulnerable: | |
Discussion
CafeLog b2 WebLog Tool Cross Site Scripting Vulnerability
CafeLog b2 WebLog Tool allows users to generate news pages and weblogs dynamically. It uses PHP and a MySQL database to generate dynamic pages.
The b2 WebLog Tool will echo data back to the browser. Some variables are assumed by the scripts to have been set by internal data, when they can be set by remote users. Since these variables are not sufficiently sanitized of HTML tags, this makes b2 WebLog Tool prone to cross-site scripting attacks.
CafeLog b2 WebLog Tool allows users to generate news pages and weblogs dynamically. It uses PHP and a MySQL database to generate dynamic pages.
The b2 WebLog Tool will echo data back to the browser. Some variables are assumed by the scripts to have been set by internal data, when they can be set by remote users. Since these variables are not sufficiently sanitized of HTML tags, this makes b2 WebLog Tool prone to cross-site scripting attacks.
Exploit / POC
CafeLog b2 WebLog Tool Cross Site Scripting Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CafeLog b2 WebLog Tool Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.