Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
BID:19357
Info
Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 19357 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2006 12:00AM |
| Updated: | Aug 07 2006 10:01PM |
| Credit: | exploitex is credited with discovering this vulnerability. |
| Vulnerable: |
Tiny Portal Tiny Portal 0.8.6 |
| Not Vulnerable: | |
Discussion
Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
Tinyportal is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
Tinyportal is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
Exploit / POC
Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Tinyportal Guestbook Multiple HTML Injection Vulnerabilities
References:
References:
- Tiny Portal Home Page (Tiny Portal )
- Tinyportal Shoutbox ([email protected])