BoardPower Forum ICQ.CGI Cross-Site Scripting Vulnerability
BID:10734
Info
BoardPower Forum ICQ.CGI Cross-Site Scripting Vulnerability
| Bugtraq ID: | 10734 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2004 12:00AM |
| Updated: | Jul 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Alexander Antipov" <[email protected]>. |
| Vulnerable: |
BoardPower BoardPower Forums |
| Not Vulnerable: | |
Discussion
BoardPower Forum ICQ.CGI Cross-Site Scripting Vulnerability
BoardPower Forum is reportedly affected by a cross-site scripting vulnerability in the icq.cgi script. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
A remote attacker can exploit this issue by creating a malicious link to the vulnerable application that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the web server and may allow for theft of cookie-based authentication credentials or other attacks.
BoardPower Forum is reportedly affected by a cross-site scripting vulnerability in the icq.cgi script. This issue is due to a failure of the application to properly sanitize user-supplied URI input.
A remote attacker can exploit this issue by creating a malicious link to the vulnerable application that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the web server and may allow for theft of cookie-based authentication credentials or other attacks.
Exploit / POC
BoardPower Forum ICQ.CGI Cross-Site Scripting Vulnerability
The following example is available:
http://www.example.com/cgi-bin/boardpower/icq.cgi?action=<script>javascript:alert('hello');</script>
The following example is available:
http://www.example.com/cgi-bin/boardpower/icq.cgi?action=<script>javascript:alert('hello');</script>
Solution / Fix
BoardPower Forum ICQ.CGI Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
BoardPower Forum ICQ.CGI Cross-Site Scripting Vulnerability
References:
References:
- BoardPower Forums (BoardPower)