JSPWiki 'Edit.jsp' Multiple Input Validation Vulnerabilities

JSPWiki is prone to multiple input-validation vulnerabilities, including a cross-site scripting issue and a file-disclosure issue, because the application fails to properly sanitize user-supplied input.

Attackers can exploit these issues to steal cookie-based authentication credentials or to obtain information that could aid in further attacks.

JSPWiki 2.4.104 and 2.5.139 are vulnerable; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus