YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
BID:18044
CVE-2006-2508 |Info
YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 18044 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2508 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2006 12:00AM |
| Updated: | Apr 29 2008 07:26PM |
| Credit: | luny is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
YourFreeWorld Stylish Text Ads Script 0 |
| Not Vulnerable: | |
Discussion
YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
Stylish Text Ads Script is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Stylish Text Ads Script is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Exploit / POC
YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
Solution:
The vendor has released an update. Please contact the vendor for information on how to obtain and apply this update.
Solution:
The vendor has released an update. Please contact the vendor for information on how to obtain and apply this update.
References
YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
References:
References: