Secunia Advisory SA38626Joomla EasyBook Component Script Insertion Vulnerability
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Jeff Channell has discovered a vulnerability in the EasyBook component for Joomla, which can be exploited by malicious people to conduct script insertion attacks. Input passed via the "Homepage" form field in index.php (when "option" is set to "com_easybook", "controller" is set to "entry", and "task" is set to "add") when creating an entry is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed. The vulnerability is confirmed in version 2.0 rc4. Other versions may also be affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
101 views | ![]() |
TYPO3 The official twitter tweet button for your page Extension Cross-Site Scripting Vulnerability![]() | |