Collabtive 'desc' Parameter HTML Injection Vulnerability
BID:67343
Info
Collabtive 'desc' Parameter HTML Injection Vulnerability
| Bugtraq ID: | 67343 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3247 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2014 12:00AM |
| Updated: | May 21 2014 12:52AM |
| Credit: | Deepak Rathore |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Collabtive 'desc' Parameter HTML Injection Vulnerability
Collabtive is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Collabtive 1.2 is vulnerable; other versions may also be affected.
Collabtive is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Collabtive 1.2 is vulnerable; other versions may also be affected.
Exploit / POC
Collabtive 'desc' Parameter HTML Injection Vulnerability
Attackers can exploit this issue using browser.
Attackers can exploit this issue using browser.
Solution / Fix
Collabtive 'desc' Parameter HTML Injection Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Collabtive 'desc' Parameter HTML Injection Vulnerability
References:
References:
- Collabtive Homepage (Collabtive)