NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
BID:18546
CVE-2006-3129 |Info
NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 18546 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3129 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2006 12:00AM |
| Updated: | Dec 31 2008 07:21PM |
| Credit: | r0t is credited with discovering these vulnerabilities. |
| Vulnerable: |
Net Concept 24 NC LinkList 1.2 |
| Not Vulnerable: |
Net Concept 24 NC LinkList 1.3.1 |
Discussion
NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
NC Linklist is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input to several parameters before returning to the user.
An attacker could exploit these vulnerabilities to inject hostile HTML and script code into the browser session of other users of the application.
NC Linklist is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input to several parameters before returning to the user.
An attacker could exploit these vulnerabilities to inject hostile HTML and script code into the browser session of other users of the application.
Exploit / POC
NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
Attackers can exploit this issue by enticing a user to follow a malicious link.
Attackers can exploit this issue by enticing a user to follow a malicious link.
Solution / Fix
NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
References:
References:
- NC Linklist (r0t)
- NC Linklist Changelog (Net Concept 24)
- NC Linklist Homepage (Net Concept 24)