OSVDB ID: 3273

Title: Geeklog File Management Plugin brokenfile.php lid Parameter XSS

Info

Disclosure

Sep 30, 2003

Discovery

Unknown

Dates

Exploit

Sep 30, 2003

Solution

Unknown

Description

Geeklog File Management Plugin contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "lid" parameter upon submission to the brokenfile.php script. This could allow a user to send a specially crafted request that would execute arbitrary code on the server leading to a loss of integrity. Note: This plugin is an optional package that is not distributed with Geeklog.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Public
OSVDB: Web Related

Solution

Upgrade to version 1.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

PortalParts.com

Geeklog File Management Plugin

Unknown or Unspecified

References

Credit

  • Lorenzo Hernandez Garcia - novappcnovappc.com - Nova Projects Professional Coding


Direct URL: http://osvdb.org/36218