Web Wiz Rich Text Editor Arbitrary HTML File Creation Vulnerability
BID:27420
Info
Web Wiz Rich Text Editor Arbitrary HTML File Creation Vulnerability
| Bugtraq ID: | 27420 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0473 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The AmnPardaz Security Research Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
Webwiz Rich Text Editor 4.0 |
| Not Vulnerable: | |
Discussion
Web Wiz Rich Text Editor Arbitrary HTML File Creation Vulnerability
Web Wiz Rich Text Editor is prone to a vulnerability that allows an attacker to create an arbitrary HTML file.
Attackers can exploit this issue to place arbitrary HTML code on the vulnerable computer. This may aid in retrieving potentially sensitive information from an unsuspecting victim; other attacks are also possible.
This issue affects Rich Text Editor 4.0; other versions may also be vulnerable.
Web Wiz Rich Text Editor is prone to a vulnerability that allows an attacker to create an arbitrary HTML file.
Attackers can exploit this issue to place arbitrary HTML code on the vulnerable computer. This may aid in retrieving potentially sensitive information from an unsuspecting victim; other attacks are also possible.
This issue affects Rich Text Editor 4.0; other versions may also be vulnerable.
Exploit / POC
Web Wiz Rich Text Editor Arbitrary HTML File Creation Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Web Wiz Rich Text Editor Arbitrary HTML File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Web Wiz Rich Text Editor Arbitrary HTML File Creation Vulnerability
References:
References: