Fire Soft Board 'User-Agent' HTTP Header HTML Injection Vulnerability
BID:48643
Info
Fire Soft Board 'User-Agent' HTTP Header HTML Injection Vulnerability
| Bugtraq ID: | 48643 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2011 12:00AM |
| Updated: | Jul 12 2011 12:00AM |
| Credit: | _jill for A-S |
| Vulnerable: |
Fire Soft Board Fire Soft Board 2.0.1 |
| Not Vulnerable: |
Fire Soft Board Fire Soft Board 2.0.2 |
Discussion
Fire Soft Board 'User-Agent' HTTP Header HTML Injection Vulnerability
Fire Soft Board is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Fire Soft Board 2.0.1 and prior versions are vulnerable.
Fire Soft Board is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Fire Soft Board 2.0.1 and prior versions are vulnerable.
Exploit / POC
Fire Soft Board 'User-Agent' HTTP Header HTML Injection Vulnerability
Attackers can exploit this issue by using a browser or readily available tools.
Attackers can exploit this issue by using a browser or readily available tools.
Solution / Fix
Fire Soft Board 'User-Agent' HTTP Header HTML Injection Vulnerability
Solution:
Reportedly, the vendor has fixed the issue; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has fixed the issue; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Fire Soft Board 'User-Agent' HTTP Header HTML Injection Vulnerability
References:
References:
- Fire Soft Board (Fire Soft Board)