WebSight Directory System Cross Site Scripting Vulnerability
BID:4357
Info
WebSight Directory System Cross Site Scripting Vulnerability
| Bugtraq ID: | 4357 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2002 12:00AM |
| Updated: | Mar 25 2002 12:00AM |
| Credit: | Credited to Jens from ppp-design <[email protected]>. |
| Vulnerable: |
WebSight Directory System WebSight Directory System 0.1 |
| Not Vulnerable: |
WebSight Directory System WebSight Directory System 0.1.1 |
Discussion
WebSight Directory System Cross Site Scripting Vulnerability
WebSight Directory System does not filter script code from URL parameters. As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running vBulletin.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
WebSight Directory System does not filter script code from URL parameters. As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running vBulletin.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
Exploit / POC
WebSight Directory System Cross Site Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WebSight Directory System Cross Site Scripting Vulnerability
Solution:
WebSight Directory System 0.1.1 addresses this issue:
WebSight Directory System WebSight Directory System 0.1
Solution:
WebSight Directory System 0.1.1 addresses this issue:
WebSight Directory System WebSight Directory System 0.1
-
WebSight Directory System WebSight-0.1.1
http://prdownloads.sourceforge.net/websight/WebSight-0.1.1.zip
References
WebSight Directory System Cross Site Scripting Vulnerability
References:
References:
- WebSight Directory System Project Homepage (WebSight Directory System )