CNIL CookieViz 'json.php' HTML Injection Vulnerability
BID:71009
Info
CNIL CookieViz 'json.php' HTML Injection Vulnerability
| Bugtraq ID: | 71009 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8352 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2014 12:00AM |
| Updated: | Nov 03 2014 12:00AM |
| Credit: | iliketurtles |
| Vulnerable: |
French National Commission On Informatics And Liberty CookieViz 1.0 |
| Not Vulnerable: | |
Solution / Fix
CNIL CookieViz 'json.php' HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
CNIL CookieViz 'json.php' HTML Injection Vulnerability
References:
References:
- CookieViz Home Page (github)
- Patch vulnerabilities : CVE-2014-8352 CVE-2014-8351 (github)
- CNIL CookieViz XSS + SQL injection leading to user pwnage (SecLists.Org)