Web Wiz Forums Registration_Rules.ASP Cross-Site Scripting Vulnerability
BID:10555
Info
Web Wiz Forums Registration_Rules.ASP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 10555 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2004 12:00AM |
| Updated: | Jun 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Ferruh Mavituna" <[email protected]>. |
| Vulnerable: |
Webwiz Web Wiz Forums 7.51 Webwiz Web Wiz Forums 7.8 Webwiz Web Wiz Forums 7.7 b Webwiz Web Wiz Forums 7.7 a Webwiz Web Wiz Forums 7.5 |
| Not Vulnerable: |
Webwiz Web Wiz Forums 7.9 |
Discussion
Web Wiz Forums Registration_Rules.ASP Cross-Site Scripting Vulnerability
A vulnerability exists in the Web Wiz Forums software that may allow a remote user to launch cross-site scripting attacks. The problem is reported to exist due to improper sanitizing of user-supplied data passed to the 'registration_rules.asp' script.
An attacker can exploit this issue to steal cookie authentication credentials, or perform other types of attacks.
A vulnerability exists in the Web Wiz Forums software that may allow a remote user to launch cross-site scripting attacks. The problem is reported to exist due to improper sanitizing of user-supplied data passed to the 'registration_rules.asp' script.
An attacker can exploit this issue to steal cookie authentication credentials, or perform other types of attacks.
Exploit / POC
Web Wiz Forums Registration_Rules.ASP Cross-Site Scripting Vulnerability
The following example is available:
registration_rules.asp?FID=%22%3E%3Cscript%3Ealert%28%27Vulnerable%2520%21%2
7%29%3C%2Fscript%3E
The following example is available:
registration_rules.asp?FID=%22%3E%3Cscript%3Ealert%28%27Vulnerable%2520%21%2
7%29%3C%2Fscript%3E
Solution / Fix
Web Wiz Forums Registration_Rules.ASP Cross-Site Scripting Vulnerability
Solution:
It is reported that this issue is fixed in Web Wiz Forums version 7.9, Symantec has not verified this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that this issue is fixed in Web Wiz Forums version 7.9, Symantec has not verified this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Web Wiz Forums Registration_Rules.ASP Cross-Site Scripting Vulnerability
References:
References:
- Web Wiz Forums Homepage (Web Wiz)
- Web Wiz Forums Registration Rules XSS Vulnerability ("Ferruh Mavituna"
)