Affected Versions:
Laura Arguello Mango Blog 1.4.1
Vulnerability description:
Mango Blog is a scalable Blog engine compiled with ColdFusion.
Mango Blog does not properly filter and submit data to archives. the term parameters on the cfm/search page are returned to users. Remote attackers can execute cross-site scripting by submitting malicious parameter requests, resulting in arbitrary HTML and script code execution in users' browser sessions. <* Reference
Http://marc.info /? L = bugtraq & m = 127290045224292 & w = 2
*>
Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! Http: // site/archives. cfm/search /? Term = % 3 Cbody % 20 onload = alert (document. cookie) % 3ESEBUG Security suggestions:
Vendor patch:
Laura Arguello
--------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mangoblog.org/