Jelsoft VBulletin Board HTML Posting Cross-Scripting Vulnerability
BID:4008
Info
Jelsoft VBulletin Board HTML Posting Cross-Scripting Vulnerability
| Bugtraq ID: | 4008 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2002 12:00AM |
| Updated: | Jan 31 2002 12:00AM |
| Credit: | This vulnerability was announced by HarryM <[email protected]> via Bugtraq on January 31, 2002. |
| Vulnerable: |
Jelsoft vBulletin 2.2 .0 |
| Not Vulnerable: |
VBulletin VBulletin 2.2.1 |
Discussion
Jelsoft VBulletin Board HTML Posting Cross-Scripting Vulnerability
vBulletin is a web-based bulletin board system. It is distributed and maintained by Jelsoft Enterprises.
It is possible to execute malicious script code in the context of the site hosting the bulletin board. This is due to vBulletin inadequately sanitizing input to the board. This could allow a board user to post malicious script code that could be used to redirect users to other pages, pop up other sites, or steal cookies. This could also result in the theft of credentials, allowing a user to gain access to the board as another user.
vBulletin is a web-based bulletin board system. It is distributed and maintained by Jelsoft Enterprises.
It is possible to execute malicious script code in the context of the site hosting the bulletin board. This is due to vBulletin inadequately sanitizing input to the board. This could allow a board user to post malicious script code that could be used to redirect users to other pages, pop up other sites, or steal cookies. This could also result in the theft of credentials, allowing a user to gain access to the board as another user.
Exploit / POC
Jelsoft VBulletin Board HTML Posting Cross-Scripting Vulnerability
This vulnerable may be exploited with a web browser.
This vulnerable may be exploited with a web browser.
Solution / Fix
Jelsoft VBulletin Board HTML Posting Cross-Scripting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Jelsoft VBulletin Board HTML Posting Cross-Scripting Vulnerability
References:
References:
- vBulletin Homepage (vBulletin)