Release date: 2011-12-01
Updated on: 2011-12-07
Affected Systems:
Geeklog geeklog 1.8.0
Unaffected system:
Geeklog geeklog 1.8.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50060
Cve id: CVE-2011-4647
Geeklog is a free and open source Web application. It allows users to create a virtual community, manage users, and post articles. Geeklog is implemented using PHP and uses MySQL as the background database.
The story creation function of Geeklog 1.8.0 has multiple code injection vulnerabilities. Successful attacks allow attackers to execute HTML and script code in the affected browsers, steal Cookie authentication creden。, or control the site appearance.
<* Source: vendor
Link: http://project.geeklog.net/tracking/view.php? Id = 1368
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Geeklog
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://geeklog.sourceforge.net/