E107 Submitted Link HTML Injection Vulnerability
BID:14508
Info
E107 Submitted Link HTML Injection Vulnerability
| Bugtraq ID: | 14508 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2005 12:00AM |
| Updated: | Aug 08 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
e107 e107 website system 0.617 e107 e107 website system 0.616 e107 e107 website system 0.603 e107 e107 website system 0.6 15a e107 e107 website system 0.6 15 e107 e107 website system 0.6 14 e107 e107 website system 0.6 13 e107 e107 website system 0.6 12 e107 e107 website system 0.6 11 e107 e107 website system 0.6 10 |
| Not Vulnerable: | |
Discussion
E107 Submitted Link HTML Injection Vulnerability
e107 is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
e107 is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
E107 Submitted Link HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
E107 Submitted Link HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
E107 Submitted Link HTML Injection Vulnerability
References:
References:
- e107 website system Homepage (e107.org)
- Multiple CMS/Forum Vulnablilties (pacifico)