pLog User Registration HTML Injection Vulnerability
BID:11082
Info
pLog User Registration HTML Injection Vulnerability
| Bugtraq ID: | 11082 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2004 12:00AM |
| Updated: | Sep 01 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Jason Thistlethwaite. |
| Vulnerable: |
pLog pLog 0.3.2 pLog pLog 0.3.1 pLog pLog 0.3 pLog pLog 0.2.1 pLog pLog 0.2 pLog pLog 0.1.2 pLog pLog 0.1.1 pLog pLog 0.1 |
| Not Vulnerable: | |
Discussion
pLog User Registration HTML Injection Vulnerability
pLog is prone to an HTML injection vulnerability that is exposed via the user registration form. Fields in the form are not adequately sanitized of HTML and script code.
This may permit execution of hostile script code when a user views pages that include the injected code. The hostile code would be rendered in the context of the site hosting the vulnerable software. Exploitation could allow for theft of cookie-based authentication credentials or other attacks.
pLog is prone to an HTML injection vulnerability that is exposed via the user registration form. Fields in the form are not adequately sanitized of HTML and script code.
This may permit execution of hostile script code when a user views pages that include the injected code. The hostile code would be rendered in the context of the site hosting the vulnerable software. Exploitation could allow for theft of cookie-based authentication credentials or other attacks.
Exploit / POC
pLog User Registration HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
pLog User Registration HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.