XOWA Unspecified Cross Site Scripting Vulnerability
BID:59404
Info
XOWA Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 59404 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2013 12:00AM |
| Updated: | Apr 23 2013 12:00AM |
| Credit: | Reported by vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
XOWA Unspecified Cross Site Scripting Vulnerability
XOWA is prone to an unspecified cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to XOWA 0.4.3 are vulnerable.
XOWA is prone to an unspecified cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to XOWA 0.4.3 are vulnerable.
Exploit / POC
XOWA Unspecified Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
References
XOWA Unspecified Cross Site Scripting Vulnerability
References:
References:
- Version 0.4.3 of XOWA Release Notes (XOWA)
- XOWA Project Page (XOWA)