Telaen CVE-2013-2623 Cross Site Scripting Vulnerability
BID:60288
CVE-2013-2623 |Info
Telaen CVE-2013-2623 Cross Site Scripting Vulnerability
| Bugtraq ID: | 60288 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2623 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2013 12:00AM |
| Updated: | Oct 10 2013 12:13AM |
| Credit: | Manuel Garcia Cardenas |
| Vulnerable: |
UebiMiau UebiMiau 2.7.10 UebiMiau UebiMiau 2.7.9 UebiMiau UebiMiau 2.7.2 |
| Not Vulnerable: | |
Discussion
Telaen CVE-2013-2623 Cross Site Scripting Vulnerability
Telaen is prone to a cross-site-scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Telaen 1.3.1 are vulnerable.
Telaen is prone to a cross-site-scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Telaen 1.3.1 are vulnerable.
Exploit / POC
Telaen CVE-2013-2623 Cross Site Scripting Vulnerability
Attackers can exploit the issue by enticing an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com/telaen/index.php?tid=default&lid=en_UK&f_email="><script>alert("XSS")</script>
Attackers can exploit the issue by enticing an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com/telaen/index.php?tid=default&lid=en_UK&f_email="><script>alert("XSS")</script>
Solution / Fix
Telaen CVE-2013-2623 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Telaen CVE-2013-2623 Cross Site Scripting Vulnerability
References:
References: