PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
BID:15294
Info
PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 15294 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3496 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Nov 18 2009 04:35PM |
| Credit: | BiPi_HaCk and Nightmare TeAmZ are credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP Handicapper PHP Handicapper |
| Not Vulnerable: |
PHP Handicapper PHP Handicapper 1.0 |
Discussion
PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
PHP Handicapper is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
PHP Handicapper is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by tricking an unsuspecting victim into following a malicious URI.
Attackers can exploit these issues by tricking an unsuspecting victim into following a malicious URI.
Solution / Fix
PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
Solution:
Vendor updates are available. Please contact the vendor for details.
Solution:
Vendor updates are available. Please contact the vendor for details.
References
PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- PHP Handicapper Web Site (PHP Handicapper )