WackoWiki Double Quoted Input HTML Injection Vulnerability
BID:11953
Info
WackoWiki Double Quoted Input HTML Injection Vulnerability
| Bugtraq ID: | 11953 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2003 12:00AM |
| Updated: | Apr 30 2003 12:00AM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
WackoWiki WackoWiki R2 |
| Not Vulnerable: |
WackoWiki WackoWiki R3 |
Discussion
WackoWiki Double Quoted Input HTML Injection Vulnerability
WackoWiki is reported affected by an HTML injection vulnerability. This issue is due to the affected software not properly sanitizing user-supplied input. Specifically the problem is related to how the application handles input that is enclosed in two instances of double-quote characters ("").
An attacker may leverage this issue to execute arbritrary script code in the browser of an unsuspecting user. This would occur in the security context of the site hosting the vulnerable software. This may facilitate the theft of cookie-based authentication credentials, loss of integrity, or other attacks.
WackoWiki is reported affected by an HTML injection vulnerability. This issue is due to the affected software not properly sanitizing user-supplied input. Specifically the problem is related to how the application handles input that is enclosed in two instances of double-quote characters ("").
An attacker may leverage this issue to execute arbritrary script code in the browser of an unsuspecting user. This would occur in the security context of the site hosting the vulnerable software. This may facilitate the theft of cookie-based authentication credentials, loss of integrity, or other attacks.
Exploit / POC
WackoWiki Double Quoted Input HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
WackoWiki Double Quoted Input HTML Injection Vulnerability
Solution:
This issue has been addressed in WackoWiki R3 and later.
WackoWiki WackoWiki R2
Solution:
This issue has been addressed in WackoWiki R3 and later.
WackoWiki WackoWiki R2
-
WackoWiki WackoWiki R4
http://wackowiki.com/WackoDownload/InEnglish
References
WackoWiki Double Quoted Input HTML Injection Vulnerability
References:
References:
- WackoWiki Release Notes (WackoWiki)