Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 384243 (CVE-2011-3010) - www-apps/twiki Cross-Site Scripting Vulnerabilities (CVE-2011-3010)
Summary: www-apps/twiki Cross-Site Scripting Vulnerabilities (CVE-2011-3010)
Status: RESOLVED FIXED
Alias: CVE-2011-3010
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://secunia.com/advisories/46123/
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-09-23 21:08 UTC by Agostino Sarubbo
Modified: 2012-03-03 20:17 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2011-09-23 21:08:33 UTC
From secunia security advisory at $URL:

Description:
1) Input passed to the "newtopic" parameter in bin/view/Main/Jump (when "template" is set to "WebCreateNewTopic") is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

2) Input passed via the URL to pages containing a slideshow presentation using the SlideShowPlugin is not properly sanitised in lib/TWiki/Plugins/SlideShowPlugin/SlideShow.pm before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerabilities are confirmed in version 5.0.2. Prior versions may also be affected.

Solution:
Update to version 5.1.0.

Original Advisory:
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2011-3010
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 22:47:30 UTC
CVE-2011-3010 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3010):
  Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0
  allow remote attackers to inject arbitrary web script or HTML via (1) the
  newtopic parameter in a WebCreateNewTopic action, related to the
  TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to
  SlideShow.pm in the SlideShowPlugin.
Comment 2 Markos Chandras (RETIRED) gentoo-dev 2012-03-03 18:47:58 UTC
package has been removed from tree
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2012-03-03 20:17:27 UTC
(In reply to comment #2)
> package has been removed from tree

Thanks. Closing noglsa since twiki was only ever ~arch.