"What I hear, I forget. What I see, I remember. What I do, I understand. - Kung Fu Tzu (Confucius)"

RSS

HIO-2012-0109 Smokeping 2.6 XSS PDF Print E-mail

Smokeping 2.6 exhibits vulnerabilities which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed to the "displaymode" parameter in the smokeping_cgi script is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability is confirmed in version 2.6.6. Prior versions may also be affected.

 

References:


CVE-2012-0790

BID: 51584

Gentoo: 399553

Nessus:N/A

OSVDB:

Red Hat: 783584

SA: 47678

XF: 

 

Solution:

Upgrade to version 2.6.7

 

 
Next >