Newscoop
  1. Newscoop
  2. CS-2464

XSS Vulnerability in front-end search

    Details

    • Type: Bug Bug
    • Status: Closed Closed
    • Priority: Critical Critical
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 3.5.0
    • Component/s: Security
    • Security Level: Everyone
    • Labels:
      None

      Description

      This is from security company:

      # Ariko-Security: Security Audits , Audyt bezpieczeństwa
      # Advisory: 751/2010

       

      ============ { Ariko-Security - Advisory #1/12/2010 } =============

      Campsite CMS XSS vulnerability

      Vendor's Description of Software and demo:
      # http://www.sourcefabric.org/ , http://campsite-demo.sourcefabric.org/en/

      Dork:
      # N/A

      Application Info:
      # Campsite CMS
      # version last 3.4.3, 3.5.0-rc1

      Vulnerability Info:
      # Type: XSS

      Time Table:
      # 10/10/2010 - Vendor notified.
      # 20/12/2010 - Release Date.

      XSS:

      # Input passed to the dumy parameter in http://[Site]/en/index.htm is not properly
      sanitised before being returned to the user.

      Sample:
      # http://site/en/index.htm

      POST: tpl=169&f_search_keywords=guest1&f_search_articles=Search&%3E%27%22%3E%3Cscript%3Ealert%2890209%29%3C%2Fscript%3E=123

      Solution:
      # Input validation should be corrected.

      Credit:
      # Discoverd By: Ariko-Security 2010

        Activity

        Hide
        Paul
        added a comment -
        Ofir, please confirm.
        Show
        Paul
        added a comment - Ofir, please confirm.
        Hide
        Ofir Gal
        added a comment -
        Validated
        Show
        Ofir Gal
        added a comment - Validated

          People

          • Assignee:
            Ofir Gal
            Reporter:
            Paul
            Implemented by:
            Holman Romero
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Time Tracking

              Estimated:
              Original Estimate - 4 hours
              4h
              Remaining:
              Remaining Estimate - 0 minutes
              0m
              Logged:
              Time Spent - 30 minutes Time Not Required
              30m