Joel Palmius Mod_Survey Survey Input Field HTML Injection Vulnerability
BID:9941
Info
Joel Palmius Mod_Survey Survey Input Field HTML Injection Vulnerability
| Bugtraq ID: | 9941 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2004 12:00AM |
| Updated: | Mar 22 2004 12:00AM |
| Credit: | Discovery is credited to Niklas Deutschmann. |
| Vulnerable: |
Joel Palmius Mod_Survey 3.2 .0-pre3 Joel Palmius Mod_Survey 3.2 .0-pre2 Joel Palmius Mod_Survey 3.2 .0-pre1 Joel Palmius Mod_Survey 3.0.16 -pre1 Joel Palmius Mod_Survey 3.0.15 -pre6 Joel Palmius Mod_Survey 3.0.15 -pre5 Joel Palmius Mod_Survey 3.0.15 -pre4 Joel Palmius Mod_Survey 3.0.15 -pre3 Joel Palmius Mod_Survey 3.0.15 -pre2 Joel Palmius Mod_Survey 3.0.15 -pre1 Joel Palmius Mod_Survey 3.0.15 Joel Palmius Mod_Survey 3.0.14 e Joel Palmius Mod_Survey 3.0.14 d Joel Palmius Mod_Survey 3.0.14 Joel Palmius Mod_Survey 3.0.13 Joel Palmius Mod_Survey 3.0.12 Joel Palmius Mod_Survey 3.0.11 Joel Palmius Mod_Survey 3.0.9 Joel Palmius Mod_Survey 3.0 .6 Joel Palmius Mod_Survey 3.0 .5 Joel Palmius Mod_Survey 3.0 .4 Joel Palmius Mod_Survey 3.0 .3 Joel Palmius Mod_Survey 3.0 .2 Joel Palmius Mod_Survey 3.0 .10 Joel Palmius Mod_Survey 3.0 .1 Joel Palmius Mod_Survey 3.0 .0 |
| Not Vulnerable: |
Joel Palmius Mod_Survey 3.2 .0-pre4 Joel Palmius Mod_Survey 3.0.16 -pre2 |
Discussion
Joel Palmius Mod_Survey Survey Input Field HTML Injection Vulnerability
Mod_Survey is prone to HTML injection attacks via survey input fields. They may permit remote attackers to persistently inject HTML and script code into surveys, which may be rendered in the web browser of administrative or other users.
Exploitation could permit for theft of cookie-based authentication credentials. Other attacks are also possible.
Mod_Survey is prone to HTML injection attacks via survey input fields. They may permit remote attackers to persistently inject HTML and script code into surveys, which may be rendered in the web browser of administrative or other users.
Exploitation could permit for theft of cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
Joel Palmius Mod_Survey Survey Input Field HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Joel Palmius Mod_Survey Survey Input Field HTML Injection Vulnerability
Solution:
This issue has been addressed in Mod_Survey versions 3.0.16-pre2 (stable branch) and 3.2.0-pre4 (development branch).
Joel Palmius Mod_Survey 3.0 .0
Joel Palmius Mod_Survey 3.0 .4
Joel Palmius Mod_Survey 3.0 .6
Joel Palmius Mod_Survey 3.0 .2
Joel Palmius Mod_Survey 3.0 .5
Joel Palmius Mod_Survey 3.0 .10
Joel Palmius Mod_Survey 3.0 .1
Joel Palmius Mod_Survey 3.0 .3
Joel Palmius Mod_Survey 3.0.11
Joel Palmius Mod_Survey 3.0.12
Joel Palmius Mod_Survey 3.0.13
Joel Palmius Mod_Survey 3.0.14 d
Joel Palmius Mod_Survey 3.0.14 e
Joel Palmius Mod_Survey 3.0.14
Joel Palmius Mod_Survey 3.0.15 -pre5
Joel Palmius Mod_Survey 3.0.15 -pre6
Joel Palmius Mod_Survey 3.0.15 -pre3
Joel Palmius Mod_Survey 3.0.15 -pre1
Joel Palmius Mod_Survey 3.0.15 -pre2
Joel Palmius Mod_Survey 3.0.15
Joel Palmius Mod_Survey 3.0.15 -pre4
Joel Palmius Mod_Survey 3.0.16 -pre1
Joel Palmius Mod_Survey 3.0.9
Joel Palmius Mod_Survey 3.2 .0-pre3
Joel Palmius Mod_Survey 3.2 .0-pre2
Joel Palmius Mod_Survey 3.2 .0-pre1
Solution:
This issue has been addressed in Mod_Survey versions 3.0.16-pre2 (stable branch) and 3.2.0-pre4 (development branch).
Joel Palmius Mod_Survey 3.0 .0
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0 .4
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0 .6
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0 .2
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0 .5
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0 .10
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0 .1
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0 .3
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.11
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.12
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.13
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.14 d
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.14 e
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.14
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.15 -pre5
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.15 -pre6
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.15 -pre3
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.15 -pre1
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.15 -pre2
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.15
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.15 -pre4
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.16 -pre1
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.0.9
-
Joel Palmius modsurvey-3.0.16-pre2.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.0.16-pr e2.tar.gz
Joel Palmius Mod_Survey 3.2 .0-pre3
-
Joel Palmius modsurvey-3.2.0-pre4.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.2.0-pre 4.tar.gz
Joel Palmius Mod_Survey 3.2 .0-pre2
-
Joel Palmius modsurvey-3.2.0-pre4.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.2.0-pre 4.tar.gz
Joel Palmius Mod_Survey 3.2 .0-pre1
-
Joel Palmius modsurvey-3.2.0-pre4.tar.gz
http://gathering.itm.mh.se/modsurvey/download/test/modsurvey-3.2.0-pre 4.tar.gz
References
Joel Palmius Mod_Survey Survey Input Field HTML Injection Vulnerability
References:
References:
- Mod_Survey Homepage (Joel Palmius)
- Mod_Survey security advisory: Script injection bug (Joel Palmius
)