Best Practical Solutions RT HTML Injection Vulnerability
BID:7509
Info
Best Practical Solutions RT HTML Injection Vulnerability
| Bugtraq ID: | 7509 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2003 12:00AM |
| Updated: | Mar 19 2015 09:11AM |
| Credit: | Discovery of this vulnerability credited to Troy Davis and the Semaphore Corporation. |
| Vulnerable: |
HappyCGI HappyMall 4.4 HappyCGI HappyMall 4.3 Bestpractical RT 1.0.7 Bestpractical RT 1.0.6 Bestpractical RT 1.0.5 Bestpractical RT 1.0.4 Bestpractical RT 1.0.3 Bestpractical RT 1.0.2 Bestpractical RT 1.0.1 Bestpractical RT 1.0 Avaya Intuity AUDIX |
| Not Vulnerable: |
Bestpractical RT 3.0.1 Bestpractical RT 3.0 Bestpractical RT 2.0.15 |
Discussion
Best Practical Solutions RT HTML Injection Vulnerability
A vulnerability has been discovered in RT which may make it prone to HTML injection attacks.
The vulnerability exists due to insufficient sanitization of user-supplied values. Specifically, the content included in message bodies is not properly sanitized of malicious HTML code.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software. Other attacks may also be possible.
A vulnerability has been discovered in RT which may make it prone to HTML injection attacks.
The vulnerability exists due to insufficient sanitization of user-supplied values. Specifically, the content included in message bodies is not properly sanitized of malicious HTML code.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software. Other attacks may also be possible.
Exploit / POC
Best Practical Solutions RT HTML Injection Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Best Practical Solutions RT HTML Injection Vulnerability
Solution:
This vulnerability does not affect RT 2.0.15 or RT 3.0. Affected users are advised to upgrade to the latest version. It should be noted that the 1.x tree is not longer being maintained.
Bestpractical RT 1.0
Bestpractical RT 1.0.1
Bestpractical RT 1.0.2
Bestpractical RT 1.0.3
Bestpractical RT 1.0.4
Bestpractical RT 1.0.5
Bestpractical RT 1.0.6
Bestpractical RT 1.0.7
Solution:
This vulnerability does not affect RT 2.0.15 or RT 3.0. Affected users are advised to upgrade to the latest version. It should be noted that the 1.x tree is not longer being maintained.
Bestpractical RT 1.0
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
Bestpractical RT 1.0.1
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
Bestpractical RT 1.0.2
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
Bestpractical RT 1.0.3
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
Bestpractical RT 1.0.4
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
Bestpractical RT 1.0.5
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
Bestpractical RT 1.0.6
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
Bestpractical RT 1.0.7
-
Best Practical Solutions rt-3-0-1.tar.gz
http://www.fsck.com/pub/rt/release/rt-3-0-1.tar.gz
References
Best Practical Solutions RT HTML Injection Vulnerability
References:
References:
- RT Homepage (Best Practical Solutions)
- Fw: [rt-users] [rt-announce] RT 1.0.7 vulnerable to Cross Site Scripting attacks ("Chris Knipe"
)