XMB Forum Member.PHP HTML Injection Vulnerability
BID:15489
Info
XMB Forum Member.PHP HTML Injection Vulnerability
| Bugtraq ID: | 15489 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3688 CVE-2005-3689 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2005 12:00AM |
| Updated: | Sep 11 2008 07:30PM |
| Credit: | trueend5 <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
XMB Forum 1.9.3 XMB Forum 1.9.2 |
| Not Vulnerable: |
XMB Forum 1.9.8 SP2 |
Discussion
XMB Forum Member.PHP HTML Injection Vulnerability
XMB Forum is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
XMB Forum is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
XMB Forum Member.PHP HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
XMB Forum Member.PHP HTML Injection Vulnerability
Solution:
A vendor update is available. Contact the vendor for more information.
Solution:
A vendor update is available. Contact the vendor for more information.
References
XMB Forum Member.PHP HTML Injection Vulnerability
References:
References: