Documents Pro CVE-2012-5184 Cross Site Scripting Vulnerability
BID:57515
Info
Documents Pro CVE-2012-5184 Cross Site Scripting Vulnerability
| Bugtraq ID: | 57515 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5184 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2013 12:00AM |
| Updated: | Jan 18 2013 12:00AM |
| Credit: | Keigo Yamazaki of LAC Co., Ltd. |
| Vulnerable: |
OliveToast Documents Pro 1.11 |
| Not Vulnerable: |
OliveToast Documents Pro 1.11.1 |
Discussion
Documents Pro CVE-2012-5184 Cross Site Scripting Vulnerability
Documents Pro is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Documents Pro 1.11.1 are vulnerable.
Documents Pro is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Documents Pro 1.11.1 are vulnerable.
Exploit / POC
Solution / Fix
Documents Pro CVE-2012-5184 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Documents Pro CVE-2012-5184 Cross Site Scripting Vulnerability
References:
References:
- Documents Pro : File Viewer (Apple Inc)
- JVN#91881278 Documents Pro vulnerable to cross-site scripting (JVN )
- JVNDB-2013-000001 Documents Pro vulnerable to cross-site scripting (JVN iPedia)
- Olive Toast Documents Pro Homepage (Olive Toast)