dadaIMC Comment Field HTML Injection Vulnerability
BID:11454
Info
dadaIMC Comment Field HTML Injection Vulnerability
| Bugtraq ID: | 11454 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2004 12:00AM |
| Updated: | Oct 18 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Brett <[email protected]>. |
| Vulnerable: |
dadaimc dadaimc 0.98.2 dadaimc dadaimc 0.98.1 dadaimc dadaimc 0.98 dadaimc dadaimc 0.97 dadaimc dadaimc 0.96 dadaimc dadaimc 0.95 |
| Not Vulnerable: | |
Discussion
dadaIMC Comment Field HTML Injection Vulnerability
dadaIMC is reported to contain an HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before including it in dynamically generated web page content.
The problem is reported to present itself due to a lack of sanitization performed on certain field data.
This may allow an attacker to inject malicious HTML and script code into the application.
dadaIMC is reported to contain an HTML injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before including it in dynamically generated web page content.
The problem is reported to present itself due to a lack of sanitization performed on certain field data.
This may allow an attacker to inject malicious HTML and script code into the application.
Exploit / POC
dadaIMC Comment Field HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
dadaIMC Comment Field HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.