Teekai's Tracking Online Cross-Site Scripting Vulnerability
BID:4924
Info
Teekai's Tracking Online Cross-Site Scripting Vulnerability
| Bugtraq ID: | 4924 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2002 12:00AM |
| Updated: | Jun 03 2002 12:00AM |
| Credit: | Credited to frog frog <[email protected]>. |
| Vulnerable: |
Teekai Tracking Online 1.0 |
| Not Vulnerable: | |
Discussion
Teekai's Tracking Online Cross-Site Scripting Vulnerability
Teekai's Tracking Online does not adequately filter HTML tags from certain URL parameters, making it prone to cross-site scripting attacks. Attackers may exploit this by creating a malicious link to a vulnerable webpage.
Teekai's Tracking Online does not adequately filter HTML tags from certain URL parameters, making it prone to cross-site scripting attacks. Attackers may exploit this by creating a malicious link to a vulnerable webpage.
Exploit / POC
Teekai's Tracking Online Cross-Site Scripting Vulnerability
The following example was provided:
http://target/page.php?action=view&id=1<script>alert(document.cookie)</script >
The following example was provided:
http://target/page.php?action=view&id=1<script>alert(document.cookie)</script >
Solution / Fix
Teekai's Tracking Online Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.