YUI Multiple Cross-Site Scripting Vulnerabilities
BID:61177
Info
YUI Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 61177 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2013 12:00AM |
| Updated: | Jul 15 2013 12:00AM |
| Credit: | Aleksandr Dobkin and Sebastian Roschke of the Google Security Team. |
| Vulnerable: |
Moodle Moodle 2.2.3 Moodle Moodle 2.2.2 Moodle Moodle 2.2.1 Moodle Moodle 2.2 |
| Not Vulnerable: | |
Discussion
YUI CVE-2013-4939 Multiple Cross-Site Scripting Vulnerabilities
YUI is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Note: The issue described by CVE-2013-4940 has been moved to BID 61523 (YUI CVE-2013-4940 Cross-Site Scripting Vulnerability) for better documentation.
YUI 3.0.0 through 3.10.0 are vulnerable.
YUI is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Note: The issue described by CVE-2013-4940 has been moved to BID 61523 (YUI CVE-2013-4940 Cross-Site Scripting Vulnerability) for better documentation.
YUI 3.0.0 through 3.10.0 are vulnerable.
Exploit / POC
YUI CVE-2013-4939 Multiple Cross-Site Scripting Vulnerabilities
To exploit these issues an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit these issues an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
YUI Multiple Cross-Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
YUI CVE-2013-4939 Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- YUI Library Homepage (YUI Library)