LAN Messenger Username Cross Site Scripting Vulnerability
BID:55877
Info
LAN Messenger Username Cross Site Scripting Vulnerability
| Bugtraq ID: | 55877 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2012 12:00AM |
| Updated: | Oct 11 2012 12:00AM |
| Credit: | Benjamin Kunz Mejri of Vulnerability Research Laboratory. |
| Vulnerable: |
LAN Messenger LAN Messenger 1.2.28 |
| Not Vulnerable: | |
Discussion
LAN Messenger Username Cross Site Scripting Vulnerability
LAN Messenger is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the context of the affected application.
LAN Messenger is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the context of the affected application.
Exploit / POC
LAN Messenger Username Cross Site Scripting Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
LAN Messenger Username Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
LAN Messenger Username Cross Site Scripting Vulnerability
References:
References:
- LAN Messenger Homepage (LAN Messenger)