P4DB URL allows cross-site scripting
| p4db-url-xss (16070) |
Description:
P4DB is vulnerable to cross-site scripting, caused by improper filtering of user-supplied input. A remote attacker could embed malicious script in a specially-crafted URL, which would be executed in the victim's Web browser within the security context of the hosting site, once the link is clicked by the victim. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials, obtain other sensitive information or perform actions as the victim.
Platforms Affected:
- Fredric Fredricson, P4DB 2.01 and prior
Remedy:
No remedy available as of July 4, 2009.
Consequences:
Obtain Information
References:
- BugTraq Mailing List, Wed May 05 2004 - 14:32:39 CDT, Multiple vulnerabilities in P4DB at http://archives.neohapsis.com/archives/bugtraq/2004-05/0046.html.
- BID-10286: P4DB Multiple Input Validation Vulnerabilities
- CVE-2004-2735: Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) SET_PREFERENCES parameter in SetPreferences.cgi; (2) BRANCH parameter in branchView.cgi; (3) FSPC and (4) COMPLETE parameters in changeByUsers.cgi; (5) FSPC, (6) LABEL, (7) EXLABEL, (8) STATUS, (9) MAXCH, (10) FIRSTCH, (11) CHOFFSETDISP, (12) SEARCHDESC, (13) SEARCH_INVERT, (14) USER, (15) GROUP, and (16) CLIENT parameters in changeList.cgi; (17) CH parameter in changeView.cgi; (18) USER parameter in clientList.cgi; (19) CLIENT parameter in clientView.cgi; (20) FSPC parameter in depotTreeBrowser.cgi; (21) FSPC parameter in depotStats.cgi; (22) FSPC, (23) REV, (24) ACT, (25) FSPC2, (26) REV2, (27) CH, and (28) CONTEXT parameters in fileDiffView.cgi; (29) F
- OSVDB ID: 5901: P4DB Multiple Unspecified XSS
- SA11559: P4DB Input Validation Vulnerabilities
- SECTRACK ID: 1010078: P4DB Input Validation Holes Let Remote Users Execute Arbitrary Shell Commands
Reported:
May 05, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
