Bugtraq ID: 14460 : Coldfusion Fusebox V4.1.0 Vulnerability

From: Adrocknaphobia (adrocknaphobia_at_gmail.com)
Date: 08/09/05

  • Next message: iDEFENSE Labs: "iDEFENSE Security Advisory 08.09.05: AWStats ShowInfoURL Remote Command Execution Vulnerability"
    Date: Tue, 9 Aug 2005 12:44:28 -0400
    To: bugtraq@securityfocus.com
    
    

    The following vulnerability is inaccurate. Fusebox is a framework
    popular with ColdFusion developers. The cross-site scripting
    vulnerability is not specific to the framework, and is clearly an
    implementation issue.

    Fusebox, as a framework, does not output any URL parameters to HTML.
    The output is controled by the application developer. FuseBox does not
    even have to generate HTML for that matter.

    Within the fusebox framework, a layout configuration file is used to
    generate output. The layout file is completely coded by the
    application developer. The official FuseBox v4.1.0 core files do not
    contain _any_ layout configuration files.

    Bugtraq ID: 14460
    Class: Input Validation Error
    CVE: CVE-MAP-NOMATCH
    Remote: Yes
    Local: No
    Published: Aug 03 2005 12:00AM
    Updated: Aug 03 2005 03:24PM
    Credit: "N.N.P" is credited with the discovery of this vulnerability.
    Vulnerable: Fusebox Fusebox 4.1 .0


  • Next message: iDEFENSE Labs: "iDEFENSE Security Advisory 08.09.05: AWStats ShowInfoURL Remote Command Execution Vulnerability"

    Relevant Pages

    • Re: Coldfusion Fusebox V4.1.0 Vulnerability
      ... List of people you could have contacted with regarding the bug: ... Subject: Coldfusion Fusebox V4.1.0 Vulnerability ... to set a standard page for errors and some filter out the script tags. ...
      (Bugtraq)
    • Coldfusion Fusebox V4.1.0 Vulnerability
      ... versions of fusebox this vulnerability is in but seeing as it affects ... Basically this vulnerability allows the execution of JS. ... to set a standard page for errors and some filter out the script tags. ... The main usage of this vulnerability would be cookie stealing. ...
      (Bugtraq)
    • [Full-disclosure] Coldfusion Fusebox V4.1.0 Vulnerability
      ... versions of fusebox this vulnerability is in but seeing as it affects ... Basically this vulnerability allows the execution of JS. ... to set a standard page for errors and some filter out the script tags. ... The main usage of this vulnerability would be cookie stealing. ...
      (Full-Disclosure)
    • FUSEBOX framework/methodology experiences?
      ... and framework to develop web apps [CF and PHP]. ... Anybody here, who ever tried Fusebox? ...
      (comp.lang.php)