XMB U2U.PHP Cross-Site Scripting Vulnerability
BID:15342
Info
XMB U2U.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15342 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3544 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2005 12:00AM |
| Updated: | Sep 10 2008 09:00PM |
| Credit: | HACKERS PAL is credited with the discovery of this vulnerability. |
| Vulnerable: |
XMB Forum 1.9.3 |
| Not Vulnerable: |
XMB Forum 1.9.8 |
Discussion
XMB U2U.PHP Cross-Site Scripting Vulnerability
XMB is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. A successful exploit could allow an attacker to steal cookie-based authentication credentials and launch other attacks.
XMB is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. A successful exploit could allow an attacker to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
XMB U2U.PHP Cross-Site Scripting Vulnerability
No exploit is required.
An example URI has been provided:
http://www.example.com/u2u.php?action=send&username=[code]
No exploit is required.
An example URI has been provided:
http://www.example.com/u2u.php?action=send&username=[code]
Solution / Fix
XMB U2U.PHP Cross-Site Scripting Vulnerability
Solution:
A vendor update is available. Contact the vendor for more information.
Solution:
A vendor update is available. Contact the vendor for more information.
References
XMB U2U.PHP Cross-Site Scripting Vulnerability
References:
References:
- Summary of Official Vendor Statements (XMB)
- XMB Forum Home Page (The XMB Group)