Red Hat CloudForms Unspecified Multiple HTML Injection Vulnerabilities
BID:66438
Info
Red Hat CloudForms Unspecified Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 66438 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0186 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2014 12:00AM |
| Updated: | Mar 11 2014 12:00AM |
| Credit: | David Jorm of the Red Hat |
| Vulnerable: |
Redhat CloudForms Management Engine 3.0 Redhat CloudForms Management Engine 2.0 Redhat CloudForms 3.0 |
| Not Vulnerable: |
Redhat CloudForms Management Engine 5.2.1 6 Redhat CloudForms Management Engine 5.2.1 Redhat CloudForms Management Engine 5.1 Redhat CloudForms Management Engine 5.0 |
Discussion
Red Hat CloudForms Unspecified Multiple HTML Injection Vulnerabilities
Red Hat CloudForms is prone to multiple unspecified HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Red Hat CloudForms 3.0 is vulnerable; other versions may also be affected.
Red Hat CloudForms is prone to multiple unspecified HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Red Hat CloudForms 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Red Hat CloudForms Unspecified Multiple HTML Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
Red Hat CloudForms Unspecified Multiple HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat CloudForms Unspecified Multiple HTML Injection Vulnerabilities
References:
References:
- Bug 895346 - (CVE-2013-0186) CVE-2013-0186 ManageIQ EVM: Stored XSS (Red Hat Bugzilla)
- CloudForms Homepage (Red Hat)
- Security Advisory Critical: cfme security, bug fix, and enhancement update (Red Hat)