0wn f0rum Script Injection Vulnerability
BID:4626
Info
0wn f0rum Script Injection Vulnerability
| Bugtraq ID: | 4626 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2002 12:00AM |
| Updated: | Apr 27 2002 12:00AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
0wn f0rum 0wn f0rum 2.1 |
| Not Vulnerable: | |
Discussion
0wn f0rum Script Injection Vulnerability
0wn f0rum is a web message board application maintained by ServicesWeb.
A script injection issue has been reported in some versions of 0wn f0rum. 0wn f0rum builds HTML content including user supplied input which is not properly stripped of scripting commands. The injected script code will execute within the context of the 0wn f0rum site when the link is followed
0wn f0rum is a web message board application maintained by ServicesWeb.
A script injection issue has been reported in some versions of 0wn f0rum. 0wn f0rum builds HTML content including user supplied input which is not properly stripped of scripting commands. The injected script code will execute within the context of the 0wn f0rum site when the link is followed
Exploit / POC
0wn f0rum Script Injection Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
0wn f0rum Script Injection Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.