Joomla! Lyftenbloggie Component Cross-Site Scripting Vulnerabilities

SECUNIA ADVISORY ID:
SA42677

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/42677/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=42677

RELEASE DATE:
2010-12-26
DESCRIPTION:
Two vulnerabilities have been discovered in the Lyftenbloggie
component for Joomla!, which can be exploited by malicious people to
conduct cross-site scripting attacks.

Input passed via the "tag" and "category" parameters to index.php
(when "option" is set to "com_lyftenbloggie") is not properly
sanitised before being returned to the user. This can be exploited to
execute arbitrary HTML and script code in a user's browser session in
context of an affected site.

The vulnerabilities are confirmed in version 1.1.0. Other versions
may also be affected.

SOLUTION:
Edit the source code to ensure that input is properly sanitised.

PROVIDED AND/OR DISCOVERED BY:
Ashiyane Digital Security Team