Xoops Private Message Box Cross-Agent Scripting Vulnerability
BID:3981
Info
Xoops Private Message Box Cross-Agent Scripting Vulnerability
| Bugtraq ID: | 3981 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0217 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Posted to the Bugtraq mailing list by Cabezon Aurélien <[email protected]>. |
| Vulnerable: |
Xoops Xoops 1.0 RC1 |
| Not Vulnerable: | |
Discussion
Xoops Private Message Box Cross-Agent Scripting Vulnerability
Xoops is open-source, freely available web portal software written in object-oriented PHP. It is back-ended by a MySQL database and will run on most Unix and Linux distributions.
Xoops includes a Private Message System for users. The image parameter of the pmlite.php script does not sufficiently filter JavaScript code. When another user views this page, the malicious script code will be executed on that user in the context of the site running Xoops.
This issue may be exploited by an attacker to steal a legitimate user's cookie-based authentication credentials, among other things.
Xoops is open-source, freely available web portal software written in object-oriented PHP. It is back-ended by a MySQL database and will run on most Unix and Linux distributions.
Xoops includes a Private Message System for users. The image parameter of the pmlite.php script does not sufficiently filter JavaScript code. When another user views this page, the malicious script code will be executed on that user in the context of the site running Xoops.
This issue may be exploited by an attacker to steal a legitimate user's cookie-based authentication credentials, among other things.
Solution / Fix
Xoops Private Message Box Cross-Agent Scripting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Xoops Private Message Box Cross-Agent Scripting Vulnerability
References:
References:
- ProManager Homepage (Promanager)