header-logo
Suggest Exploit
vendor:
Chipmunk Products
by:
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Chipmunk Products
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

Chipmunk Products Cross-Site Scripting Vulnerabilities

The Chipmunk products are prone to multiple cross-site scripting vulnerabilities. These vulnerabilities occur due to a failure in the applications to properly sanitize user-supplied input. An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user within the context of the affected site. This can lead to the theft of cookie-based authentication credentials and facilitate other attacks.

Mitigation:

To mitigate the risk of these vulnerabilities, it is recommended to implement proper input validation and sanitization techniques in the affected applications. Additionally, the use of output encoding when displaying user-supplied data can help prevent cross-site scripting attacks.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/15149/info
  
Chipmunk products are prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
  
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. 

http://www.example.com/topsites/recommend.php?ID='%3C/a>%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E