| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801741 |
| Category: | Web application abuses |
| Title: | Joomla 'Lyftenbloggie' Component Cross-Site Scripting Vulnerabilities |
| Summary: | Check if Joomla Lyftenbloggie component is vulnerable for XSS attack |
| Description: | Overview: This host is running Joomla and is prone to Multiple Cross Site Scripting vulnerabilities. Vulnerability Insight: - Input passed via the 'tag' and 'category' parameters to 'index.php' (when 'option' is set to 'com_lyftenbloggie') is not properly sanitised before being returned to the user. Impact: Successful exploitation will let attackers to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. Impact Level: Application. Affected Software/OS: Joomla Lyftenbloggie component version 1.1.0 Fix: No solution or patch is available as of 10th February 2011. Information regarding this issue will be updated once the solution details are available. For updates refer to http://www.lyften.com/products/lyften-bloggie.html References: http://secunia.com/advisories/42677 http://packetstormsecurity.org/files/view/96761/joomlalyftenbloggie-xss.txt |
| Cross-Ref: |
BugTraq ID: 45468 Common Vulnerability Exposure (CVE) ID: CVE-2010-4718 http://packetstormsecurity.org/files/view/96761/joomlalyftenbloggie-xss.txt http://www.securityfocus.com/bid/45468 http://secunia.com/advisories/42677 |
| Copyright | Copyright (C) 2011 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|