|
Feeds -
Exploits
|
|
Written by Isfahan University of Technology - Computer Emergency Response Team
|
|
Tuesday, 03 March 2009 22:02 |
Yektaweb Academic Web Tools CMS Multiple Cross Site Scripting Vulnerabilities
-\\Bugtraq ID: 33944
-\\Class: Input Validation Error
-\\CVE:
-\\Remote: Yes
-\\Local: No
-\\Published: Mar 02 2009 12:00AM
-\\Updated: Mar 03 2009 06:26PM
-\\Credit: Isfahan University of Technology - Computer Emergency Response Team
-\\Vulnerable: Yektaweb Academic Webtools CMS 1.5.7 Yektaweb Academic Webtools CMS 1.4.2.8
-\\Discussion Yektaweb Academic Web Tools CMS is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Academic Web Tools CMS 1.5.7 is vulnerable; other versions may also be affected.
-\\Exploit(s)/PoC(s): An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
=============================================================== 33944.txt ^^^^^^^^^^ http://www.example.com/login.php?slct_pg_id=53&sid=1*/--></script><script>alert(188017)</script>&slc_lang=fa http://www.example.com/page_arch.php?slc_lang=fa&sid=1&logincase=*/--></script><script>alert(188017)</script> http://www.example.com/page.php?sid=1&slc_lang=en&redirect=*/--></script><script>alert(188017)</script>
-\\Solution Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at:
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
.
-\\References(s) --Academic Web Tools CMS Homepage http://www.yektaweb.com (Yektaweb) --YEKTA WEB Academic Web Tools CMS Multiple XSS http://www.securityfocus.com/archive/1/50135 (
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
)
|