ZeroForum User-Embedded Scripting Vulnerability
BID:4394
Info
ZeroForum User-Embedded Scripting Vulnerability
| Bugtraq ID: | 4394 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0474 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 29 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Reported by altomo <[email protected]>. |
| Vulnerable: |
ZeroForum ZeroForum 1.0 |
| Not Vulnerable: | |
Discussion
ZeroForum User-Embedded Scripting Vulnerability
ZeroForum allows forum users to post images in messages. It is reportedly possible for attackers to cause script code to be embedded in the the image tags.
This may allow for an attacker to compromise the accounts of other users.
ZeroForum allows forum users to post images in messages. It is reportedly possible for attackers to cause script code to be embedded in the the image tags.
This may allow for an attacker to compromise the accounts of other users.
Exploit / POC
ZeroForum User-Embedded Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ZeroForum User-Embedded Scripting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.