XSS bug in PEAR::Text_Wiki 1.1.0

by Michael Mayer - Sat, Jun 10 2006

This bug was found and reported by Michael Mayer (Liquid Bytes) on Jun 9, 2006.

Description

The raw markup rule of PEAR::Text_Wiki (release 1.1.0) is a very simple way to inject any JavaScript or other possibly malicious code into a Wiki page (even if the html markup rule is disabled!). This is known as cross-site scripting (XSS).

Example

See the Heise Security Forum (German). You can test it in the YaWiki Sandbox.

Solution

Upgrade to the next stable release. This bug has been fixed in CVS.

External References

Print this page  PDF version

More News

3 Trackbacks

You must be logged in to post a comment.

Trackback URL for this entry: http://www.awf-cms.org/trackback/AWF_Document/170

Login

or create a new account

Username


Password


Language

Latest Release

Version: 2.1.5
Date: 2006-07-02 19:13:44
Download