phpLinkat Multiple Cross Site Scripting Vulnerabilities
BID:5890
Info
phpLinkat Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 5890 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2002 12:00AM |
| Updated: | Oct 04 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Sp.IC <[email protected]>. |
| Vulnerable: |
phpLinkat phpLinkat 0.1 .0 |
| Not Vulnerable: | |
Discussion
phpLinkat Multiple Cross Site Scripting Vulnerabilities
Reportedly, phpLinkat is prone to cross site scripting attacks.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link containing HTML and script code. The attacker-supplied HTML and script code may be executed on a web client in the context of the site hosting phpLinkat.
Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Reportedly, phpLinkat is prone to cross site scripting attacks.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link containing HTML and script code. The attacker-supplied HTML and script code may be executed on a web client in the context of the site hosting phpLinkat.
Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Exploit / POC
phpLinkat Multiple Cross Site Scripting Vulnerabilities
The following proof of concepts were provided:
http://target/showcat.php?catid=<Script>JavaScript:alert('test');</Script>
http://target/addyoursite.php?catid=<Script>JavaScript:alert('test');</Script>
The following proof of concepts were provided:
http://target/showcat.php?catid=<Script>JavaScript:alert('test');</Script>
http://target/addyoursite.php?catid=<Script>JavaScript:alert('test');</Script>