WebCT Campus Edition HTML Tags HTML Injection Vulnerabilities
BID:10357
Info
WebCT Campus Edition HTML Tags HTML Injection Vulnerabilities
| Bugtraq ID: | 10357 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2004 12:00AM |
| Updated: | May 17 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to "spiffomatic 64" <[email protected]>. |
| Vulnerable: |
WebCT WebCT Campus Edition 4.1.1 .5 WebCT WebCT Campus Edition 4.1 SP2 Hotfix 40832 WebCT WebCT Campus Edition 4.1 WebCT WebCT Campus Edition 4.0 SP3 Hotfix 40833 WebCT WebCT Campus Edition 4.0 |
| Not Vulnerable: | |
Discussion
WebCT Campus Edition HTML Tags HTML Injection Vulnerabilities
WebCT Campus Edition is reportedly affected by multiple HTML tag HTML injection vulnerabilities. These issues are due to a failure of the application to properly validate and sanitize user input.
It has been reported that this issue can be exploited to steal authentication credentials and other sensitive information; giving an attacker full control of an unsuspecting user's account. Other attacks may also be possible.
WebCT Campus Edition is reportedly affected by multiple HTML tag HTML injection vulnerabilities. These issues are due to a failure of the application to properly validate and sanitize user input.
It has been reported that this issue can be exploited to steal authentication credentials and other sensitive information; giving an attacker full control of an unsuspecting user's account. Other attacks may also be possible.
Exploit / POC
WebCT Campus Edition HTML Tags HTML Injection Vulnerabilities
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
WebCT Campus Edition HTML Tags HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WebCT Campus Edition HTML Tags HTML Injection Vulnerabilities
References:
References:
- WebCT Homepage (WebCT)
- [Full-Disclosure] WebCT: Cross Site Scripting Vulnerability ("spiffomatic 64"
)