Leszek Krupinski L-Forum Message Header Script Injection Vulnerability
BID:5462
Info
Leszek Krupinski L-Forum Message Header Script Injection Vulnerability
| Bugtraq ID: | 5462 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1458 CVE-2002-1459 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery of this vulnerability credited to Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
Leszek Krupinski L-Forum 2.4 .0 |
| Not Vulnerable: | |
Discussion
Leszek Krupinski L-Forum Message Header Script Injection Vulnerability
A script injection vulnerability has been reported in L-Forum 2.4.0. Malicious messages may be posted to the forum which include arbitrary HTML content, including JavaScript code. If the message is then viewed by another user of the system, the supplied script code will execute within the context of the vulnerable site.
This flaw is due to insufficient filtering of the 'From', 'E-mail' and 'Subject' fields of a message post.
A script injection vulnerability has been reported in L-Forum 2.4.0. Malicious messages may be posted to the forum which include arbitrary HTML content, including JavaScript code. If the message is then viewed by another user of the system, the supplied script code will execute within the context of the vulnerable site.
This flaw is due to insufficient filtering of the 'From', 'E-mail' and 'Subject' fields of a message post.
Exploit / POC
Leszek Krupinski L-Forum Message Header Script Injection Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Leszek Krupinski L-Forum Message Header Script Injection Vulnerability
Solution:
A patch has been made available:
Leszek Krupinski L-Forum 2.4 .0
Solution:
A patch has been made available:
Leszek Krupinski L-Forum 2.4 .0
-
Leszek Krupinski Security patch for L-Forum 2.4.0
http://sourceforge.net/tracker/download.php?group_id=53716&atid=471343 &file_id=26687&aid=579278
References
Leszek Krupinski L-Forum Message Header Script Injection Vulnerability
References:
References:
- L-Forum Home Page (Leszek Krupinski)