PHPReactor Browse.PHP Cross-Site Scripting Vulnerability
BID:5939
Info
PHPReactor Browse.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 5939 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2002 12:00AM |
| Updated: | Oct 10 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Arab VieruZ <[email protected]>. |
| Vulnerable: |
Ekilat LLC php(Reactor) 1.2.7 pl1 |
| Not Vulnerable: | |
Discussion
PHPReactor Browse.PHP Cross-Site Scripting Vulnerability
php(Reactor) is prone to cross-site scripting attacks.
An attacker may create a malicious link to a php(Reactor) site which contains malicious HTML and script code. If this link is visited by a web user, the attacker-supplied code will execute in their web client, in the security context of the php(Reactor) site.
This may allow for theft of cookie-based authentication credentials from legitimate authenticated users. Other attacks are also possible.
This issue has been reported in php(Reactor) version 1.2.7pl1. Other versions may also be affected.
php(Reactor) is prone to cross-site scripting attacks.
An attacker may create a malicious link to a php(Reactor) site which contains malicious HTML and script code. If this link is visited by a web user, the attacker-supplied code will execute in their web client, in the security context of the php(Reactor) site.
This may allow for theft of cookie-based authentication credentials from legitimate authenticated users. Other attacks are also possible.
This issue has been reported in php(Reactor) version 1.2.7pl1. Other versions may also be affected.
Exploit / POC
PHPReactor Browse.PHP Cross-Site Scripting Vulnerability
The following proof-of-concept example was provided:
http://www.example.com/forums/browse.php?fid=3&tid=46&go=<script>JavaScript:alert('test');</script>
The following proof-of-concept example was provided:
http://www.example.com/forums/browse.php?fid=3&tid=46&go=<script>JavaScript:alert('test');</script>
Solution / Fix
PHPReactor Browse.PHP Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPReactor Browse.PHP Cross-Site Scripting Vulnerability
References:
References:
- php(Reactor) Homepage (php(Reactor))