RDoc CVE-2013-0256 Cross Site Scripting Vulnerability
BID:57785
Info
RDoc CVE-2013-0256 Cross Site Scripting Vulnerability
| Bugtraq ID: | 57785 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0256 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2013 12:00AM |
| Updated: | May 07 2015 05:01PM |
| Credit: | Evgeny Ermakov |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 |
| Not Vulnerable: | |
Discussion
RDoc CVE-2013-0256 Cross Site Scripting Vulnerability
RDoc is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
RDoc versions 2.3.0 through 3.12 and prior 4.0.0.preview2.1 are vulnerable.
RDoc is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
RDoc versions 2.3.0 through 3.12 and prior 4.0.0.preview2.1 are vulnerable.
Exploit / POC
RDoc CVE-2013-0256 Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
RDoc CVE-2013-0256 Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
RDoc CVE-2013-0256 Cross Site Scripting Vulnerability
References:
References:
- Fix CVE-2013-0256, an XSS exploit in RDoc (RDoc)
- Moderate: CloudForms Common 1.1.2 update (Red Hat)
- openSUSE-SU-2013:0376-1: moderate: ruby19 to 1.9.3 p385 (OpenSUSE)
- RDoc 2.3.0 through 3.12 XSS Exploit (RDoc)
- RDoc HomePage (RDoc)
- Moderate: Subscription Asset Manager 1.2.1 update (Red Hat)
- RHSA-2013:0701-1: Moderate: ruby193-ruby, rubygem-json and rubygem-rdoc security (Red Hat)
- rubygem packages security update (Red Hat)