Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Joshua Miller

#40230of 53,633
6.8Total CVSS
Vulnerabilities · 1
PT-2004-1464
6.8
2004-03-18
Livejournal · Livejournal · CVE-2004-0310
**Name of the Vulnerable Software and Affected Versions** LiveJournal versions 1.0 through 1.1 **Description** A cross-site scripting issue allows remote attackers to execute Javascript as other users via the stylesheet. The vulnerability is due to the stylesheet not stripping the semicolon or parentheses, which can be exploited to inject malicious code. This can be demonstrated by using a background:url in the stylesheet to execute arbitrary Javascript. **Recommendations** For LiveJournal versions 1.0 and 1.1, consider restricting access to the stylesheet feature until a fix is available, and avoid using user-supplied input in the stylesheet to minimize the risk of exploitation.