SECUNIA ADVISORY ID:
SA42677
VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/42677/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=42677
RELEASE DATE:
2010-12-26
DESCRIPTION:
Two vulnerabilities have been discovered in the Lyftenbloggie
component for Joomla!, which can be exploited by malicious people to
conduct cross-site scripting attacks.
Input passed via the "tag" and "category" parameters to index.php
(when "option" is set to "com_lyftenbloggie") is not properly
sanitised before being returned to the user. This can be exploited to
execute arbitrary HTML and script code in a user's browser session in
context of an affected site.
The vulnerabilities are confirmed in version 1.1.0. Other versions
may also be affected.
SOLUTION:
Edit the source code to ensure that input is properly sanitised.
PROVIDED AND/OR DISCOVERED BY:
Ashiyane Digital Security Team