Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Flyspray Multiple Information Disclosure, HTML Injection, and Cross-Site Scripting Vulnerabilities

Flyspray is prone to an information-disclosure issue, an HTML-injection issue, and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues determine valid usernames and passwords via brute-force attacks or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, and launch other attacks.

These issues affect Flyspray 0.9.9 to 0.9.9.4.







 

Privacy Statement
Copyright 2009, SecurityFocus