CVE-2014-9559 SnipSnap XSS (Cross-Site Scripting)
CVE-2014-9559 SnipSnap XSS (Cross-Site Scripting) Security Vulnerabilities
Exploit Title: SnipSnap /snipsnap-search? query Parameter XSS
Product: SnipSnap
Vulnerable Versions: 0.5.2a 1.0b1 1.0b2
Tested Version: 0.5.2a 1.0b1 1.0b2
Advisory Publication: Jan 30, 2015
Latest Update: Jan 30, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2014-9559
CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6
Credit: Wang Jing [MAS, Nanyang Technological University (NTU), Singapore]
Advisory Details:
(1) Vendor & Product Description
Vendor:
SnipSnap
Product & Version:
SnipSnap
0.5.2a
1.0b1
1.0b2
Vendor URL & Download:
Product Description:
“SnipSnap is a user friendly content management system with features such as wiki and weblog. “
(2) Vulnerability Details:
SnipSnap has a security problem. It can be exploited by XSS attacks.
(2.1) The vulnerability occurs at “snipsnap-search?” page with “query” parameter.
References:
https://www.securityfocus.com/bid/72397
https://www.cvedetails.com/cve/CVE-2014-9559/
https://seclists.org/fulldisclosure/2015/Feb/1
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9559
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9559
https://permalink.gmane.org/gmane.comp.security.fulldisclosure/1539
https://static-173-79-223-25.washdc.fios.verizon.net/?a=139222176300014&r=1&w=2
https://ittechnology.lofter.com/post/1cfbf60d_5c34005
https://lists.kde.org/?a=139222176300014&r=1&w=2
https://itinfotech.tumblr.com/post/110692217346/securitypost-cve-2014-9559-snipsnap-xss
https://marc.info/?a=139222176300014&r=1&w=4
https://itprompt.blogspot.com/2015/02/cve-2014-9559-snipsnap-xss-cross-site.html