Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
29 Jun. 2012
Summary
Post Revolution is prone to multiple html-injection vulnerabilities and a denial-of-service vulnerability because the application fails to sufficiently sanitize user-supplied input.
Vulnerable Systems:
* Post Revolution PostRev 0.8.0c
Immune Systems:
* Post Revolution PostRev 0.8.0c-2
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Vendor Status:
The vendor has released an update and an advisory.