NPDS BB HTML Injection Vulnerability
BID:10676
Info
NPDS BB HTML Injection Vulnerability
| Bugtraq ID: | 10676 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2004 12:00AM |
| Updated: | Jul 07 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Benjamin Tolman <[email protected]>. |
| Vulnerable: |
NPDS NPDS 4.8 |
| Not Vulnerable: | |
Discussion
NPDS BB HTML Injection Vulnerability
A vulnerability is reported in NPDS BB that may allow a remote attacker to execute HTML and script code in a user's browser.
The problem exists due to insufficient sanitization of user-supplied input. It may be possible for an attacker to include malicious HTML code in a vulnerable text field. The injected code would be interpreted by the browser of a user visiting the vulnerable site when the malicious HTML code is viewed.
A vulnerability is reported in NPDS BB that may allow a remote attacker to execute HTML and script code in a user's browser.
The problem exists due to insufficient sanitization of user-supplied input. It may be possible for an attacker to include malicious HTML code in a vulnerable text field. The injected code would be interpreted by the browser of a user visiting the vulnerable site when the malicious HTML code is viewed.
Exploit / POC
NPDS BB HTML Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NPDS BB HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
NPDS BB HTML Injection Vulnerability
References:
References:
- NPDS Homepage (NPDS)
- Npds BB HTML Injection (Benjamin Tolman
)