PHPRank Banner Script Code Injection Vulnerability
BID:5946
Info
PHPRank Banner Script Code Injection Vulnerability
| Bugtraq ID: | 5946 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2002 12:00AM |
| Updated: | Oct 10 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Jedi/Sector One <[email protected]>. |
| Vulnerable: |
phpRank phpRank 1.8 |
| Not Vulnerable: | |
Discussion
PHPRank Banner Script Code Injection Vulnerability
phpRank is a freely available web site link sharing script. It is available for Unix, Linux, and Microsoft operating systems.
It has been reported that phpRank does not properly filter some forms of input. When a user submits a site to the banner list, it is possible for the user to insert arbitrary HTML or script code in the banner URL. This could allow a remote user to execute arbitrary code in the browser of clients visiting the site.
phpRank is a freely available web site link sharing script. It is available for Unix, Linux, and Microsoft operating systems.
It has been reported that phpRank does not properly filter some forms of input. When a user submits a site to the banner list, it is possible for the user to insert arbitrary HTML or script code in the banner URL. This could allow a remote user to execute arbitrary code in the browser of clients visiting the site.
Exploit / POC
PHPRank Banner Script Code Injection Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
PHPRank Banner Script Code Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.