Decoda "[video]" Tag Script Insertion Vulnerability
by Carol~
- 5/3/12 3:41 PM
In Reply to: VULNERABILITIES / FIXES - May 03, 2012 by Carol~
Release Date : 2012-05-03
Criticality level : Moderately critical
Impact : Cross Site Scripting
Where : From remote
Solution Status : Vendor Patch
Software: Decoda 3.x
Description:
RedTeam Pentesting has discovered a vulnerability in Decoda, which can be exploited by malicious people to conduct script insertion attacks.
Input passed via "[video]" tags to the markup parser is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.
The vulnerability is confirmed in version 3.3.1. Prior versions may also be affected.
Solution:
Update to version 3.3.2.
Provided and/or discovered by:
RedTeam Pentesting
Original Advisory:
RedTeam Pentesting:
http://www.redteam-pentesting.de/en/advisories/rt-sa-2012-002/-php-decoda-cross-site-scripting-in-video-tags
Decoda:
https://github.com/milesj/php-decoda/commits/master
http://secunia.com/advisories/48931/

Moderator
CNET Staff
Samsung Staff
Dell Staff