PHP Ticket Cross Site Scripting Vulnerability
BID:5124
Info
PHP Ticket Cross Site Scripting Vulnerability
| Bugtraq ID: | 5124 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2002 12:00AM |
| Updated: | Jun 28 2002 12:00AM |
| Credit: | Published in a PHP Ticket changelog. |
| Vulnerable: |
PHP Ticket PHP Ticket 0.5 |
| Not Vulnerable: |
PHP Ticket PHP Ticket 0.6 |
Discussion
PHP Ticket Cross Site Scripting Vulnerability
PHP Ticket is a "To Do List" tracking system maintained by MrSpiff.
A cross site scripting vulnerability is present in PHP Ticket. The application does not properly sanitize HTML before it is included in PHP generated HTML pages.
PHP Ticket is a "To Do List" tracking system maintained by MrSpiff.
A cross site scripting vulnerability is present in PHP Ticket. The application does not properly sanitize HTML before it is included in PHP generated HTML pages.
Exploit / POC
PHP Ticket Cross Site Scripting Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHP Ticket Cross Site Scripting Vulnerability
Solution:
MrSpiff has addressed this issue in version 0.6:
PHP Ticket PHP Ticket 0.5
Solution:
MrSpiff has addressed this issue in version 0.6:
PHP Ticket PHP Ticket 0.5
-
MrSpiff phpticket-latest
http://www.shell.linux.se/spiff/code/phpticket-latest.tar.gz