Pinboard Task List HTML Injection Vulnerability
BID:4988
Info
Pinboard Task List HTML Injection Vulnerability
| Bugtraq ID: | 4988 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2002 12:00AM |
| Updated: | Jun 10 2002 12:00AM |
| Credit: | This issue was publicized in the project's release notes. |
| Vulnerable: |
Pinboard Pinboard 1.0 |
| Not Vulnerable: |
Pinboard Pinboard 1.1 |
Discussion
Pinboard Task List HTML Injection Vulnerability
Pinboard does not sufficiently filter HTML tags from form fields. This may allow users of Pinboard to inject arbitrary HTML and script code into tasklists.
This may enable malicious users to hijack web content or potentially steal cookie-based authentication credentials.
Pinboard does not sufficiently filter HTML tags from form fields. This may allow users of Pinboard to inject arbitrary HTML and script code into tasklists.
This may enable malicious users to hijack web content or potentially steal cookie-based authentication credentials.
Exploit / POC
Pinboard Task List HTML Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.