Justin Hagstrom Auto Directory Index Cross-Site Scripting Vulnerability
BID:9056
Info
Justin Hagstrom Auto Directory Index Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9056 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2003 12:00AM |
| Updated: | Nov 17 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to David Sopas Ferreira. |
| Vulnerable: |
Justin Hagstrom Auto Directory Index 1.2.3 |
| Not Vulnerable: |
Justin Hagstrom Auto Directory Index 1.2.4 |
Discussion
Justin Hagstrom Auto Directory Index Cross-Site Scripting Vulnerability
It has been reported that Auto Directory Index is prone to a cross-site scripting vulnerability. The issue is reported to exist due insufficient sanitization of user-supplied data through the 'dir' parameter, which will then be included in a dynamically generated web page. The problem may allow a remote attacker to execute HTML or script code in the browser of a user following a malicious link created by an attacker.
Auto Directory Index version 1.2.3 is reported to be prone to this issue, however other versions may be affected as well.
It has been reported that Auto Directory Index is prone to a cross-site scripting vulnerability. The issue is reported to exist due insufficient sanitization of user-supplied data through the 'dir' parameter, which will then be included in a dynamically generated web page. The problem may allow a remote attacker to execute HTML or script code in the browser of a user following a malicious link created by an attacker.
Auto Directory Index version 1.2.3 is reported to be prone to this issue, however other versions may be affected as well.
Exploit / POC
Justin Hagstrom Auto Directory Index Cross-Site Scripting Vulnerability
The following proof of concept has been provided:
http://www.example.com/index.php?dir=<script>malicious_code</script>
The following proof of concept has been provided:
http://www.example.com/index.php?dir=<script>malicious_code</script>
Solution / Fix
Justin Hagstrom Auto Directory Index Cross-Site Scripting Vulnerability
Solution:
The vendor has released version of 1.2.4 of the software that address this issue. Users may obtain the new version from the referenced SourceForge site.
Justin Hagstrom Auto Directory Index 1.2.3
Solution:
The vendor has released version of 1.2.4 of the software that address this issue. Users may obtain the new version from the referenced SourceForge site.
Justin Hagstrom Auto Directory Index 1.2.3
-
SourceForge AutoIndex PHP 1.2.4
http://sourceforge.net/project/showfiles.php?group_id=82718
References
Justin Hagstrom Auto Directory Index Cross-Site Scripting Vulnerability
References:
References:
- Auto Directory Index (SourceForge)