Ultimate PHP Remote Injection Vulnerabilities
BID:14350
Info
Ultimate PHP Remote Injection Vulnerabilities
| Bugtraq ID: | 14350 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2005 12:00AM |
| Updated: | Jul 21 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ultimate PHP Board Ultimate PHP Board 1.9.6 Ultimate PHP Board Ultimate PHP Board 1.9 Ultimate PHP Board Ultimate PHP Board 1.8.2 Ultimate PHP Board Ultimate PHP Board 1.8 Ultimate PHP Board Ultimate PHP Board 1.0 b Ultimate PHP Board Ultimate PHP Board 1.0 final beta Ultimate PHP Board Ultimate PHP Board 1.0 |
| Not Vulnerable: | |
Discussion
Ultimate PHP Remote Injection Vulnerabilities
Ultimate PHP is prone to multiple HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Ultimate PHP is prone to multiple HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
Ultimate PHP Remote Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Ultimate PHP Remote Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ultimate PHP Remote Injection Vulnerabilities
References:
References:
- Ultimate PHP Board Homepage (Ultimate PHP Board)
- UPB GOLD 1.9.6 Cross Site Scripting Attack poc exploit by rgod (rgod)