EZ Publish Logging HTML Injection Vulnerability
BID:7138
Info
EZ Publish Logging HTML Injection Vulnerability
| Bugtraq ID: | 7138 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2003 12:00AM |
| Updated: | Mar 18 2003 12:00AM |
| Credit: | Discovery is credited to Ertan Kurt <[email protected]>. |
| Vulnerable: |
eZ Systems eZ publish 2.2.7 |
| Not Vulnerable: | |
Discussion
EZ Publish Logging HTML Injection Vulnerability
eZ publish may allow malicious HTML and script code contained in requests to be logged. When an administrative user views this information through eZ publish, the hostile HTML and script code could be interpreted in their browser. This could allow for compromise of cookie-based credentials or other possible attacks.
This issue was reported in eZ publish 2.2.7. Other versions may also be affected.
eZ publish may allow malicious HTML and script code contained in requests to be logged. When an administrative user views this information through eZ publish, the hostile HTML and script code could be interpreted in their browser. This could allow for compromise of cookie-based credentials or other possible attacks.
This issue was reported in eZ publish 2.2.7. Other versions may also be affected.
Exploit / POC
EZ Publish Logging HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
EZ Publish Logging HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EZ Publish Logging HTML Injection Vulnerability
References:
References:
- eZ Publish Homepage (eZ Publish)
- Some XSS vulns (Ertan Kurt
)