OpenConf Paper Submission HTML Injection Vulnerability
BID:12554
Info
OpenConf Paper Submission HTML Injection Vulnerability
| Bugtraq ID: | 12554 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0407 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Discovered by RedTeam. |
| Vulnerable: |
OpenConf OpenConf 1.0 4 |
| Not Vulnerable: |
OpenConf OpenConf 1.10 |
Discussion
OpenConf Paper Submission HTML Injection Vulnerability
OpenConf is prone to an HTML injection vulnerability. This is due to insufficient validation of data supplied through paper submissions within the OpenConf system.
This may permit an attacker to inject hostile HTML and script code into the session of a user who is reviewing the submitted paper. Theft of cookie-based credentials is possible in addition to other attacks.
OpenConf is prone to an HTML injection vulnerability. This is due to insufficient validation of data supplied through paper submissions within the OpenConf system.
This may permit an attacker to inject hostile HTML and script code into the session of a user who is reviewing the submitted paper. Theft of cookie-based credentials is possible in addition to other attacks.
Exploit / POC
OpenConf Paper Submission HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
OpenConf Paper Submission HTML Injection Vulnerability
Solution:
This issue has been addressed in OpenConf 1.10.
OpenConf OpenConf 1.0 4
Solution:
This issue has been addressed in OpenConf 1.10.
OpenConf OpenConf 1.0 4
-
OpenConf OpenConf 1.10
http://www.zakongroup.com/technology/openconf-download.php
References
OpenConf Paper Submission HTML Injection Vulnerability
References:
References: