Release date: 2012-09-07
Updated on:
Affected Systems:
Apache Group Wicket 1.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55445
Cve id: CVE-2012-3373
Wicket provides an object-oriented method for developing Web-based Dynamic UI applications.
Apache Wicket versions earlier than 1.4.21 and 1.5.8 add encoded NULL bytes to the URL pointing to the Wicket application, inject JS statements into ajax, send malicious URLs to users, and induce them to open, as a result, arbitrary HTML and script code are executed in the user browser session of the affected site.
<* Source: Thomas Heigl
Link: http://secunia.com/advisories/50555/
Https://wicket.apache.org/2012/09/06/cve-2012-3373.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
Apache Group has released a Security Bulletin (cve-2012-3373) and patches for this:
Cve-2012-3373: CVE-2012-3373-Apache Wicket XSS vulnerability
Link: https://wicket.apache.org/2012/09/06/cve-2012-3373.html