Joomla! ALFContact Component Unspecified Cross-Site Scripting Vulnerability
BID:59441
Info
Joomla! ALFContact Component Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 59441 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2013 12:00AM |
| Updated: | Apr 24 2013 12:00AM |
| Credit: | Reported via the Joomla! Vulnerable Extensions List. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Joomla! ALFContact Component Unspecified Cross-Site Scripting Vulnerability
The ALFContact component for Joomla! is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
ALFContact 3.1.3 is vulnerable; other versions may also be affected.
The ALFContact component for Joomla! is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
ALFContact 3.1.3 is vulnerable; other versions may also be affected.
Exploit / POC
Joomla! ALFContact Component Unspecified Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
References
Joomla! ALFContact Component Unspecified Cross-Site Scripting Vulnerability
References:
References:
- ALFContact Homepage (ALFSoft)
- January 2012 and onwards Reported Vulnerable Extensions (Joomla!)
- Joomla! Homepage (Joomla )