MojoGallery Multiple HTML Injection Vulnerabilities
BID:19431
CVE-2006-4104 |Info
MojoGallery Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 19431 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Aug 09 2006 07:30PM |
| Credit: | tugra is credited with discovering this vulnerability. |
| Vulnerable: |
MojoScripts mojoGallery 0 |
| Not Vulnerable: | |
Discussion
MojoGallery Multiple HTML Injection Vulnerabilities
MojoGallery is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker could exploit these issues to inject hostile HTML and script code into the browser session of other users of the application.
MojoGallery is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker could exploit these issues to inject hostile HTML and script code into the browser session of other users of the application.
Exploit / POC
MojoGallery Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
MojoGallery Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
MojoGallery Multiple HTML Injection Vulnerabilities
References:
References:
- Mojo Gallery Web Site (MojoScripts)
- MojoScripts' xss vulnerable ([email protected])