hdweGUEST Multiple HTML Injection Vulnerabilities
BID:19053
CVE-2006-3765 |Info
hdweGUEST Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 19053 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2006 12:00AM |
| Updated: | Jul 19 2006 08:17PM |
| Credit: | Tamriel is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
HUTTENLOCHER WEBDESIGN hdweGUEST 2.1.1 |
| Not Vulnerable: | |
Discussion
hdweGUEST Multiple HTML Injection Vulnerabilities
hdweGUEST is prone to multiple HTML-injection because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
The issues affect version 2.1.1 and earlier.
hdweGUEST is prone to multiple HTML-injection because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
The issues affect version 2.1.1 and earlier.
Exploit / POC
hdweGUEST Multiple HTML Injection Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
hdweGUEST Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].