Marked Module Multiple Content Injection Vulnerabilities
BID:67356
Info
Marked Module Multiple Content Injection Vulnerabilities
| Bugtraq ID: | 67356 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3743 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2014 12:00AM |
| Updated: | May 16 2014 12:52AM |
| Credit: | Adam Baldwin |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Marked Module Multiple Content Injection Vulnerabilities
Marked Module is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied content to be passed in context of the affected browser; Other attacks are also possible.
Marked Module 0.3.0 and earlier versions are vulnerable.
Marked Module is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied content to be passed in context of the affected browser; Other attacks are also possible.
Marked Module 0.3.0 and earlier versions are vulnerable.
Exploit / POC
Marked Module Multiple Content Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
Marked Module Multiple Content Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Marked Module Multiple Content Injection Vulnerabilities
References:
References: