Webformatique Reservation Manager `index.php' Cross Site Scripting Vulnerability
BID:43003
Info
Webformatique Reservation Manager `index.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 43003 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2009 12:00AM |
| Updated: | Sep 02 2009 12:00AM |
| Credit: | Moudi |
| Vulnerable: |
webformatique Reservation Manager 0 |
| Not Vulnerable: | |
Discussion
Webformatique Reservation Manager `index.php' Cross Site Scripting Vulnerability
Webformatique Reservation Manager is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Webformatique Reservation Manager 2.4.0 is vulnerable; other versions may also be affected.
Webformatique Reservation Manager is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Webformatique Reservation Manager 2.4.0 is vulnerable; other versions may also be affected.
Solution / Fix
Webformatique Reservation Manager `index.php' Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any patches. If you feel we are in error or if you are aware of more recent
information, please mail us at: [email protected].
Solution:
Currently we are not aware of any patches. If you feel we are in error or if you are aware of more recent
information, please mail us at: [email protected].