Core APM HTML Injection Vulnerability
BID:4920
Info
Core APM HTML Injection Vulnerability
| Bugtraq ID: | 4920 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2002 12:00AM |
| Updated: | May 29 2002 12:00AM |
| Credit: | This issue was publicized in the project changelog. |
| Vulnerable: |
Core APM Core APM 1.0 1 Core APM Core APM 1.0 0 Core APM Core APM 0.9.1 0 |
| Not Vulnerable: |
Core APM Core APM 1.11 Core APM Core APM 1.10 |
Discussion
Core APM HTML Injection Vulnerability
Core APM does not sanitize HTML tags from form fields. As a result, attackers may pass arbitrary HTML and script code into form fields, which will end up being displayed in Core APM webpages.
Core APM does not sanitize HTML tags from form fields. As a result, attackers may pass arbitrary HTML and script code into form fields, which will end up being displayed in Core APM webpages.
Exploit / POC
Core APM HTML Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.