Eprayer Your Name Field HTML Injection Vulnerability
BID:18485
CVE-2006-3538 |Info
Eprayer Your Name Field HTML Injection Vulnerability
| Bugtraq ID: | 18485 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2006 12:00AM |
| Updated: | Jun 19 2006 03:40PM |
| Credit: | Luny is credited with discovering this vulnerability. |
| Vulnerable: |
EPrayer EPrayer ALPHA |
| Not Vulnerable: | |
Discussion
Eprayer Your Name Field HTML Injection Vulnerability
Eprayer is prone to an HTML-injection vulnerability because it fails to properly sanitize HTML and script code from user-supplied input to the prayer request form.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
Eprayer is prone to an HTML-injection vulnerability because it fails to properly sanitize HTML and script code from user-supplied input to the prayer request form.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
Exploit / POC
Eprayer Your Name Field HTML Injection Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
Eprayer Your Name Field HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
References
Eprayer Your Name Field HTML Injection Vulnerability
References:
References:
- EPrayer Homepage (Eprayer)
- EPrayer (Luny)