SecurityAlert : 833 CVE : CVE-2006-2177 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : admin subjectzero net Published : 04.05.2006
Affected Software :
geoBlog
Advisory Content :
Summary:
Software: geoBlog
Sowtware's Web Site: http://sourceforge.net/projects/bitdamaged/
Versions: MOD_1.0
Issue: Our research team has been working arounf on this software since the
last 2hrs and have come up succesfully with bug in the product .geoBLog is
prone to multiple XSS vulnerability .An attacker may leverage this issue to
have arbitrary script code executed in the browser of an unsuspecting user
in the context of the affected site. This may help the attacker steal
cookie-based authentication credentials and launch other attacks.the
exploit is tested on geoBlog 1.0.
========================================
PROOF OF CONCEPT : http://www.subjectzero.net/research/sblog.htm
========================================
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.