Typo3 Log HTML Injection Vulnerability
BID:6983
Info
Typo3 Log HTML Injection Vulnerability
| Bugtraq ID: | 6983 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2003 12:00AM |
| Updated: | Feb 28 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Martin Eiszner <[email protected]>. |
| Vulnerable: |
Typo3 Typo3 3.5 b5 |
| Not Vulnerable: |
Typo3 Typo3 3.5 .0 |
Discussion
Typo3 Log HTML Injection Vulnerability
Remote attackers may inject malicious HTML and script code into log files. When these logs are viewed, the hostile code will be interpreted in the web client of the user viewing the logs. This may allow for theft of administrative cookie-based authentication credentials and other attacks.
Remote attackers may inject malicious HTML and script code into log files. When these logs are viewed, the hostile code will be interpreted in the web client of the user viewing the logs. This may allow for theft of administrative cookie-based authentication credentials and other attacks.
Exploit / POC
Typo3 Log HTML Injection Vulnerability
The following exploit was submitted:
The following exploit was submitted:
Solution / Fix
Typo3 Log HTML Injection Vulnerability
Solution:
The vendor has released a new version of Typo3.
Fix available:
Typo3 Typo3 3.5 b5
Solution:
The vendor has released a new version of Typo3.
Fix available:
Typo3 Typo3 3.5 b5
-
Typo3 typo3_src-3.5.0.tgz
http://212.242.92.43/t3dl/typo3_src-3.5.0.tgz
References
Typo3 Log HTML Injection Vulnerability
References:
References:
- Synnefoims Homepage (synnefoims)
- typo3 issues (Martin Eiszner
)