Thatware Cross-Site Scripting Vulnerability
BID:4175
Info
Thatware Cross-Site Scripting Vulnerability
| Bugtraq ID: | 4175 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2002 12:00AM |
| Updated: | Feb 25 2002 12:00AM |
| Credit: | Discovered by Koen. |
| Vulnerable: |
Thatware Thatware 0.5.3 |
| Not Vulnerable: | |
Discussion
Thatware Cross-Site Scripting Vulnerability
Thatware is a bulletin board, discussion and portal framework. Thatware is very similar to Slascode, which is behind the popular Slashdot page.
A cross site scripting vulnerability exists in Thatware. By constructing a URL to a vulnerable site, an attacker may insert script commands into the displayed page. If a user of the Thatware system follows such a link, the script will execute in the context of the Thatware page. This may lead to the compromise of that user's Thatware account, through the theft of cookie data.
Thatware is a bulletin board, discussion and portal framework. Thatware is very similar to Slascode, which is behind the popular Slashdot page.
A cross site scripting vulnerability exists in Thatware. By constructing a URL to a vulnerable site, an attacker may insert script commands into the displayed page. If a user of the Thatware system follows such a link, the script will execute in the context of the Thatware page. This may lead to the compromise of that user's Thatware account, through the theft of cookie data.
References
Thatware Cross-Site Scripting Vulnerability
References:
References:
- Hack In The Box's Advisory (Hack in the box)
- Thatware Homepage (Thatware)