PT-2004-1464 · Livejournal · Livejournal

Joshua Miller

·

Publicado

2004-03-18

·

Atualizado

2017-07-11

·

CVE-2004-0310

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LiveJournal versions 1.0 through 1.1
Description A cross-site scripting issue allows remote attackers to execute Javascript as other users via the stylesheet. The vulnerability is due to the stylesheet not stripping the semicolon or parentheses, which can be exploited to inject malicious code. This can be demonstrated by using a background:url in the stylesheet to execute arbitrary Javascript.
Recommendations For LiveJournal versions 1.0 and 1.1, consider restricting access to the stylesheet feature until a fix is available, and avoid using user-supplied input in the stylesheet to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0310

Produtos afetados

Livejournal