PT-2004-1464 · Livejournal · Livejournal
Joshua Miller
·
Published
2004-03-18
·
Updated
2017-07-11
·
CVE-2004-0310
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
LiveJournal versions 1.0 through 1.1
Description
A cross-site scripting issue allows remote attackers to execute Javascript as other users via the stylesheet. The vulnerability is due to the stylesheet not stripping the semicolon or parentheses, which can be exploited to inject malicious code. This can be demonstrated by using a background:url in the stylesheet to execute arbitrary Javascript.
Recommendations
For LiveJournal versions 1.0 and 1.1, consider restricting access to the stylesheet feature until a fix is available, and avoid using user-supplied input in the stylesheet to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Livejournal