PT-2004-1464 · Livejournal · Livejournal
Joshua Miller
·
Publicado
2004-03-18
·
Atualizado
2017-07-11
·
CVE-2004-0310
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
LiveJournal versions 1.0 through 1.1
Description
A cross-site scripting issue allows remote attackers to execute Javascript as other users via the stylesheet. The vulnerability is due to the stylesheet not stripping the semicolon or parentheses, which can be exploited to inject malicious code. This can be demonstrated by using a background:url in the stylesheet to execute arbitrary Javascript.
Recommendations
For LiveJournal versions 1.0 and 1.1, consider restricting access to the stylesheet feature until a fix is available, and avoid using user-supplied input in the stylesheet to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Livejournal