YA Book City Field HTML-injection Vulnerability
BID:23626
Info
YA Book City Field HTML-injection Vulnerability
| Bugtraq ID: | 23626 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2007 12:00AM |
| Updated: | Apr 24 2007 07:30PM |
| Credit: | omnipresent is credited with the discovery of this vulnerability. |
| Vulnerable: |
YA Book YA Book 0.98-alpha |
| Not Vulnerable: | |
Discussion
YA Book City Field HTML-injection Vulnerability
YA Book is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input before displaying it in dynamically generated content.
An attacker could exploit this vulnerability to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
YA Book 0.98-alpha is vulnerable to this issue; prior versions may also be affected.
YA Book is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input before displaying it in dynamically generated content.
An attacker could exploit this vulnerability to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
YA Book 0.98-alpha is vulnerable to this issue; prior versions may also be affected.
Exploit / POC
YA Book City Field HTML-injection Vulnerability
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
YA Book City Field HTML-injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
YA Book City Field HTML-injection Vulnerability
References:
References: