Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  BBaCE <= 3.5 (includes/functio
ns.php) Remote File Include Vulnerability

  digishop v 4.0.0 Xss Vuln.

  Dayfox Blog v2.0 Remote file include

From:Paolo Perego <thesp0nge_(at)_gmail.com>
Date:03.10.2006
Subject:Pebble 2.0.0 RC[1,2] XSS vulnerability

Software: Pebble
Version: 2.0.0 RC1 - 2.0.0 RC2
Author: Simon Brown
Homepage: http://pebble.sourceforge.net

Abstract
Pebble is a blogging system built upon java and XML. There is no
database to store the data into but just XML is used instead.

Description

Vulnerability: XSS vulnerability in "search" functionality. Query
string wasn't parsed for HTML and while printing it out for "Search
with google" link, the XSS can be done.

Workaround
Disable "Search with google" link in the user result page or, better,
update to the latest version in subversion.

History

Author contacted: 20 september
Author replyed: 20 september
Patch published in Subversion archive: 27 september


Disclaimer:

This advisory intended to be informational. No responsibility is taken
for its misuse.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server