|
|
| |
| ClipBucket is affected by XSS vulnerabilities in version 2.6. |
| |
Credit:
The original article can be found at: http://www.mavitunasecurity.com/xss-vulnerabilities-in-clipbucket/
The information has been provided by Canberk Bolat.
|
| |
Vulnerable Systems:
* ClipBucket 2.6
Details:
Params: (cat, sort, time, seo_cat_name, cat, sort, time, page, seo_cat_name)
Files: (channels.php, collections.php, groups.php, photos.php, videos.php)
http://example.com/search_result.php?query=3&type='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x005B39)%3C/script%3E&submit=Search
signup.php (POST: username)
Vendor Status:
Currently we are not aware of any updates from the vendor.
Disclosure Timeline:
05/12/2011 - First Contact
03/01/2012 - Second Contact - No Reply
19/10/2012 - Advisory Released
|
|
blog comments powered by
|
|