YaPiG Comment Field HTML Injection Vulnerability
BID:11452
Info
YaPiG Comment Field HTML Injection Vulnerability
| Bugtraq ID: | 11452 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2004 12:00AM |
| Updated: | Oct 18 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
YaPiG YaPig 0.92 b |
| Not Vulnerable: |
YaPiG YaPig 0.93 u |
Discussion
YaPiG Comment Field HTML Injection Vulnerability
YaPiG is reported to contain an HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before including it in dynamically generated web page content.
The problem is reported to present itself due to a lack of sanitization performed on certain field data.
This may allow an attacker to inject malicious HTML and script code into the application.
YaPiG is reported to contain an HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before including it in dynamically generated web page content.
The problem is reported to present itself due to a lack of sanitization performed on certain field data.
This may allow an attacker to inject malicious HTML and script code into the application.
Exploit / POC
YaPiG Comment Field HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
YaPiG Comment Field HTML Injection Vulnerability
Solution:
The vendor has released an update to address this and other issues:
YaPiG YaPig 0.92 b
Solution:
The vendor has released an update to address this and other issues:
YaPiG YaPig 0.92 b
-
YaPig yapig-0.93u.tar.gz
http://prdownloads.sourceforge.net/yapig/yapig-0.93u.tar.gz?download
References
YaPiG Comment Field HTML Injection Vulnerability
References:
References:
- Release Notes: yapig-0.93u (YaPig)
- YaPiG Home Page (YaPiG)