CVE-2005-4455: Medium severity LiveJournal LiveJournal vulnerability
cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.
cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.
The issue is remotely exploitable and requires no authentication. An attacker needs to be able to submit XML content that reaches cleanhtml.pl, such as through vectors including customview.cgi.
Successful exploitation allows injection of scripting languages through the XSL namespace in XML. The provided CVSS vector indicates integrity impact, with no stated confidentiality or availability impact.
LiveJournal installations using cleanhtml.pl 1.129 from CVS before December 13, 2005 should be checked. The affected software is identified as LiveJournal LiveJournal.
A patch is available. Update cleanhtml.pl to a version that includes the correction made after the affected CVS revision/date.