Douran FollowWeb Portal Register.ASPX Cross-Site Scripting Vulnerability
BID:16302
Info
Douran FollowWeb Portal Register.ASPX Cross-Site Scripting Vulnerability
| Bugtraq ID: | 16302 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0373 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2006 12:00AM |
| Updated: | Sep 01 2009 10:22PM |
| Credit: | behn00d from the Crouz Security Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
Douran Portal FollowWeb 0 |
| Not Vulnerable: |
Douran Portal FollowWeb 3.9.6.0 |
Discussion
Douran FollowWeb Portal Register.ASPX Cross-Site Scripting Vulnerability
FollowWeb is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
FollowWeb is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Douran FollowWeb Portal Register.ASPX Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Douran FollowWeb Portal Register.ASPX Cross-Site Scripting Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Douran FollowWeb Portal Register.ASPX Cross-Site Scripting Vulnerability
References:
References:
- FollowWeb Web Site (Douran Portal)