Pixie CMS Multiple Cross Site Scripting Vulnerabilities
BID:67768
Info
Pixie CMS Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 67768 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3786 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2014 12:00AM |
| Updated: | May 30 2014 12:00AM |
| Credit: | Simone Memoli and Filippos Mastrogiannis |
| Vulnerable: |
Lucid Crew Pixie 1.04 |
| Not Vulnerable: | |
Discussion
Pixie CMS Multiple Cross Site Scripting Vulnerabilities
Pixie CMS is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Pixie CMS 1.04 is vulnerable; other versions may also be affected.
Pixie CMS is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Pixie CMS 1.04 is vulnerable; other versions may also be affected.
Exploit / POC
Pixie CMS Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Pixie CMS Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.