NBBC '[img]' BBCode Tag HTML Injection Vulnerability
BID:43879
Info
NBBC '[img]' BBCode Tag HTML Injection Vulnerability
| Bugtraq ID: | 43879 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2217 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2009 12:00AM |
| Updated: | Jun 22 2009 12:00AM |
| Credit: | freakmod |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
NBBC '[img]' BBCode Tag HTML Injection Vulnerability
NBBC is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to NBBC 1.4.2 are vulnerable.
NBBC is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to NBBC 1.4.2 are vulnerable.
Exploit / POC
NBBC '[img]' BBCode Tag HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
NBBC '[img]' BBCode Tag HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
NBBC '[img]' BBCode Tag HTML Injection Vulnerability
References:
References:
- Injection in [img] tags? (SourceForge)
- Injection in [img] tags? (SourceForge)
- NBBC Project Page (SourceForge)
- NBBC: The New BBCode Parser (SourceForge)
- Security: [img] tags emit raw text for invalid URLs - ID: 2809888 (SourceForge)