Class-1 Forum Users.PHP Cross Site Scripting Vulnerabilities
BID:14261
Info
Class-1 Forum Users.PHP Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 14261 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2005 12:00AM |
| Updated: | Jul 14 2005 12:00AM |
| Credit: | Credit is given to [email protected] for the discovery of these vulnerabilities. |
| Vulnerable: |
class-1 forum 0.24.4 class-1 forum 0.23.2 |
| Not Vulnerable: | |
Discussion
Class-1 Forum Users.PHP Cross Site Scripting Vulnerabilities
Vulnerabilities exist in class-1 Forum that allows an attacker to perform cross-site scripting attacks.
These issues are due to a failure of the application to properly sanitize user-supplied input.
Vulnerabilities exist in class-1 Forum that allows an attacker to perform cross-site scripting attacks.
These issues are due to a failure of the application to properly sanitize user-supplied input.
Exploit / POC
Class-1 Forum Users.PHP Cross Site Scripting Vulnerabilities
Exploit code is not required.
Exploit code is not required.
Solution / Fix
Class-1 Forum Users.PHP Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Class-1 Forum Users.PHP Cross Site Scripting Vulnerabilities
References:
References:
- class-1 Forum Software Cross site scripting (Lostmon
) - Class-1 Website (Class-1)