u5CMS CVE-2015-1575 Multiple Cross Site Scripting and HTML Injection Vulnerabilities
BID:73208
Info
u5CMS CVE-2015-1575 Multiple Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 73208 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-1575 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2015 12:00AM |
| Updated: | Mar 18 2015 12:00AM |
| Credit: | Gjoko Krstic |
| Vulnerable: |
Yuba U5cms 3.9.3 Yuba U5cms 3.9.2 |
| Not Vulnerable: |
Yuba U5cms 3.9.4 |
Discussion
u5CMS CVE-2015-1575 Multiple Cross Site Scripting and HTML Injection Vulnerabilities
u5CMS is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
u5CMS is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Exploit / POC
u5CMS CVE-2015-1575 Multiple Cross Site Scripting and HTML Injection Vulnerabilities
Attacker can exploit HTML-injection issues using a web browser. To exploit Cross-site scripting issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Attacker can exploit HTML-injection issues using a web browser. To exploit Cross-site scripting issues, an attacker must entice an unsuspecting victim into following a malicious URI.
References
u5CMS CVE-2015-1575 Multiple Cross Site Scripting and HTML Injection Vulnerabilities
References:
References:
- u5CMS 3.9.3 Multiple Stored And Reflected XSS Vulnerabilities (Gjoko Krstic)
- u5CMS Homepage (yuba)