MilliScripts Register.PHP Cross-Site Scripting Vulnerability
BID:15792
Info
MilliScripts Register.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15792 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2005 12:00AM |
| Updated: | Dec 09 2005 12:00AM |
| Credit: | Security Nation is credited with the discovery of this vulnerability. |
| Vulnerable: |
MilliScripts MilliScripts 1.4 |
| Not Vulnerable: | |
Discussion
MilliScripts Register.PHP Cross-Site Scripting Vulnerability
MilliScripts is prone to a cross-site scripting vulnerability. This is due to a lack of proper input validation.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
MilliScripts is prone to a cross-site scripting vulnerability. This is due to a lack of proper input validation.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
MilliScripts Register.PHP Cross-Site Scripting Vulnerability
No exploit is required.
An example URI has been provided:
http://www.example.com/red_14/register.php?do=register2&domainname=%22%3E%3Cs
cript%20src=www.example.com/script.js%3E%3C/script%3E&ext=www.example.com
No exploit is required.
An example URI has been provided:
http://www.example.com/red_14/register.php?do=register2&domainname=%22%3E%3Cs
cript%20src=www.example.com/script.js%3E%3C/script%3E&ext=www.example.com
Solution / Fix
MilliScripts Register.PHP Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MilliScripts Register.PHP Cross-Site Scripting Vulnerability
References:
References: