PHProjekt Chatroom Text Submission HTML Injection Vulnerability
BID:13286
Info
PHProjekt Chatroom Text Submission HTML Injection Vulnerability
| Bugtraq ID: | 13286 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 20 2005 12:00AM |
| Updated: | Apr 20 2005 12:00AM |
| Credit: | Discovery credited to Secure Science Corporation. |
| Vulnerable: |
PHProjekt PHProjekt 4.2 PHProjekt PHProjekt 3.2 a PHProjekt PHProjekt 3.2 PHProjekt PHProjekt 3.1 a PHProjekt PHProjekt 3.1 PHProjekt PHProjekt 3.0 PHProjekt PHProjekt 2.4 a PHProjekt PHProjekt 2.4 PHProjekt PHProjekt 2.3 PHProjekt PHProjekt 2.2 PHProjekt PHProjekt 2.1 a PHProjekt PHProjekt 2.1 PHProjekt PHProjekt 2.0.1 PHProjekt PHProjekt 2.0 |
| Not Vulnerable: | |
Discussion
PHProjekt Chatroom Text Submission HTML Injection Vulnerability
PHProjekt is prone to an HTML injection vulnerability in the Chatroom text submission form. The application fails to sanitize user-supplied input that is in turn displayed to all users of the chatroom.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
PHProjekt is prone to an HTML injection vulnerability in the Chatroom text submission form. The application fails to sanitize user-supplied input that is in turn displayed to all users of the chatroom.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
PHProjekt Chatroom Text Submission HTML Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PHProjekt Chatroom Text Submission HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHProjekt Chatroom Text Submission HTML Injection Vulnerability
References:
References:
- PHProjekt Homepage (PHProjekt Team)
- Secure Science Corporation Application Software Advisory 055 (SSC Advisory Notice
)