Decoda "[video]" Tag Script Insertion Vulnerability

by Carol~ Moderator - 5/3/12 3:41 PM

In Reply to: VULNERABILITIES / FIXES - May 03, 2012 by Carol~ Moderator

Release Date : 2012-05-03

Criticality level : Moderately critical
Impact : Cross Site Scripting
Where : From remote
Solution Status : Vendor Patch

Software: Decoda 3.x

Description:
RedTeam Pentesting has discovered a vulnerability in Decoda, which can be exploited by malicious people to conduct script insertion attacks.

Input passed via "[video]" tags to the markup parser is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.

The vulnerability is confirmed in version 3.3.1. Prior versions may also be affected.

Solution:
Update to version 3.3.2.

Provided and/or discovered by:
RedTeam Pentesting

Original Advisory:
RedTeam Pentesting:
http://www.redteam-pentesting.de/en/advisories/rt-sa-2012-002/-php-decoda-cross-site-scripting-in-video-tags

Decoda:
https://github.com/milesj/php-decoda/commits/master

http://secunia.com/advisories/48931/