Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Joshua Miller

#40230de 53,635
6.8CVSS total
Vulnerabilidades · 1
PT-2004-1464
6.8
2004-03-18
Livejournal · Livejournal · CVE-2004-0310
**Name of the Vulnerable Software and Affected Versions** LiveJournal versions 1.0 through 1.1 **Description** A cross-site scripting issue allows remote attackers to execute Javascript as other users via the stylesheet. The vulnerability is due to the stylesheet not stripping the semicolon or parentheses, which can be exploited to inject malicious code. This can be demonstrated by using a background:url in the stylesheet to execute arbitrary Javascript. **Recommendations** For LiveJournal versions 1.0 and 1.1, consider restricting access to the stylesheet feature until a fix is available, and avoid using user-supplied input in the stylesheet to minimize the risk of exploitation.