Powerboards error.php Cross Site Scripting Vulnerability
BID:4472
Info
Powerboards error.php Cross Site Scripting Vulnerability
| Bugtraq ID: | 4472 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2002 12:00AM |
| Updated: | Apr 09 2002 12:00AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
Powerboards Powerboards 2.2 b |
| Not Vulnerable: | |
Discussion
Powerboards error.php Cross Site Scripting Vulnerability
Powerboards is a bulletin board application developed in PHP.
A Cross Site Scripting issue has been reported in some versions of Powerboards. The error page error.php builds HTML content including user supplied input which is not properly stripped of scripting commands. An attacker may construct a link to this page which includes malicious script, which will execute within the context of the Powerboards site when the link is followed.
Powerboards is a bulletin board application developed in PHP.
A Cross Site Scripting issue has been reported in some versions of Powerboards. The error page error.php builds HTML content including user supplied input which is not properly stripped of scripting commands. An attacker may construct a link to this page which includes malicious script, which will execute within the context of the Powerboards site when the link is followed.
Exploit / POC
Powerboards error.php Cross Site Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Powerboards error.php Cross Site Scripting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Powerboards error.php Cross Site Scripting Vulnerability
References:
References:
- Multiples trous dans le forum Powerboard (frog frog )
- Powerboards Homepage (Powerboards)