Monday, July 19, 2010

Pixie: XSS Vulnerability

Users of Pixie please be advised of a(n) XSS vulnerability that has been identified.



To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
HTB22468: XSS vulnerability in Pixie
Vulnerability Details:

User can execute arbitrary JavaScript code within the vulnerable application.



The vulnerability exists due to failure in the site settings saving script to properly sanitize user-supplied input in "keywords" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment