XMB Forum Magic Lantern forumdisplay.php Cross Site Scripting Vulnerability
BID:4944
Info
XMB Forum Magic Lantern forumdisplay.php Cross Site Scripting Vulnerability
| Bugtraq ID: | 4944 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2002 12:00AM |
| Updated: | Jun 05 2002 12:00AM |
| Credit: | Discovered by val2 <[email protected]>. |
| Vulnerable: |
The XMB Group XMB Forum 1.6 Magic Lantern |
| Not Vulnerable: | |
Discussion
XMB Forum Magic Lantern forumdisplay.php Cross Site Scripting Vulnerability
XMB Forum 1.6 Magic Lantern is a web based discussion forum.
XMB Forum Magic Lantern does not filter script code from URL parameters, making it prone to cross-site scripting attacks. Attacker-supplied script code may be included in a malicious link to the 'forumdisplay.php' script. Such a malicious link might be included in a HTML e-mail or on a malicious webpage.
This may enable a remote attacker to steal cookie-based authentication credentials from legitimate users of a host running XMB Forum.
XMB Forum 1.6 Magic Lantern is a web based discussion forum.
XMB Forum Magic Lantern does not filter script code from URL parameters, making it prone to cross-site scripting attacks. Attacker-supplied script code may be included in a malicious link to the 'forumdisplay.php' script. Such a malicious link might be included in a HTML e-mail or on a malicious webpage.
This may enable a remote attacker to steal cookie-based authentication credentials from legitimate users of a host running XMB Forum.
Exploit / POC
XMB Forum Magic Lantern forumdisplay.php Cross Site Scripting Vulnerability
Security Bugware has provided the following exploit information:
http://www.xmbforum.com/community/forumdisplay.php?fid=21"><script>alert(document.cookie)</script>
Security Bugware has provided the following exploit information:
http://www.xmbforum.com/community/forumdisplay.php?fid=21"><script>alert(document.cookie)</script>
Solution / Fix
XMB Forum Magic Lantern forumdisplay.php Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
XMB Forum Magic Lantern forumdisplay.php Cross Site Scripting Vulnerability
References:
References:
- XMB Forum Cross Site Scripting security hole (Security Bugware)
- XMB Forum Home Page (The XMB Group)