TUCoPS :: HP Unsorted C :: va1383.htm

flatpress 0.804, CVE-2008-4120 Cross Site Scripting (XSS) Vulnerabilitiy
Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804, CVE-2008-4120
Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804, CVE-2008-4120



This is a MIME-formatted message.  If you see this text it means that your
E-mail software does not support MIME-formatted messages.

--=_zucker.schokokeks.org-1778-1222360127-0001-2
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804,
CVE-2008-4120 

References

http://www.datensalat.eu/~fabian/cve/CVE-2008-4120-flatpress.html 
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4120 
http://www.flatpress.org/ 

Description

FlatPress is an open-source standard-compliant multi-lingual extensible
blogging engine which does not require a DataBase Management System to
work. 

Example

Assuming flatpress is installed on http://localhost/flatpress/, anybody 
could inject JavaScript:

action="http://localhost/flatpress/login.php">
action="http://localhost/flatpress/login.php">
action="http://localhost/flatpress/contact.php">
Workaround/Fix Update to 0.804.1. Disclosure Timeline 2008-09-25 Vendor contacted 2008-09-25 Vendor released 0.804.1 2008-09-25 Published advisory CVE Information The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2008-4120 to this issue. This is a candidate for inclusion in the CVE list (http://cve.mitre.org/), which standardizes names for security problems. Credits and copyright This vulnerability was discovered by Fabian Fingerle (published with help from Hanno Boeck [0]). It's licensed under the creative commons attribution license [1]. Fabian Fingerle, 2008-09-25, http://www.fabian-fingerle.de [0] http://www.hboeck.de [1] http://creativecommons.org/licenses/by/3.0/de/ --=_zucker.schokokeks.org-1778-1222360127-0001-2 Content-Type: application/pgp-signature; name="signature.asc" Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (GNU/Linux) iEYEARECAAYFAkjbvDoACgkQ/aNqCatBq4UWIACfXqxzKt+/XlXn5XzKMUaUhkx4 axIAoKykTYMc/Prs9uhu4R5b71b/VSvQ =sv2L -----END PGP SIGNATURE----- --=_zucker.schokokeks.org-1778-1222360127-0001-2--

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH