Alexandria / SourceForge Cross Site Scripting Vulnerability
BID:7223
Info
Alexandria / SourceForge Cross Site Scripting Vulnerability
| Bugtraq ID: | 7223 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2003 12:00AM |
| Updated: | Mar 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Ulf Harnhammar. |
| Vulnerable: |
VA Software SourceForge Enterprise Edition 2.7 VA Software SourceForge Enterprise Edition 2.5 Alexandria Alexandria 2.5 Alexandria Alexandria 2.0 |
| Not Vulnerable: |
VA Software SourceForge Enterprise Edition 3.2 |
Discussion
Alexandria / SourceForge Cross Site Scripting Vulnerability
Alexandria does not adequately filter some HTML code thus making it prone to cross-site scripting attacks. It is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software. The attacker may hijack the session of the legitimate by using cookie-based authentication credentials. Other attacks are also possible.
Alexandria does not adequately filter some HTML code thus making it prone to cross-site scripting attacks. It is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software. The attacker may hijack the session of the legitimate by using cookie-based authentication credentials. Other attacks are also possible.
Solution / Fix
Alexandria / SourceForge Cross Site Scripting Vulnerability
Solution:
Alexandria is no longer being actively maintained however, VA Software's SourceForge Enterprise Edition is believed to be invulnerable to this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Alexandria is no longer being actively maintained however, VA Software's SourceForge Enterprise Edition is believed to be invulnerable to this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.