Cyboards PHP Lite Multiple Cross Site Scripting Vulnerabilities
BID:6596
Info
Cyboards PHP Lite Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 6596 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2003 12:00AM |
| Updated: | Jan 13 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to [email protected]. |
| Vulnerable: |
Cyboards Cyboards PHP Lite 1.25 Cyboards Cyboards PHP Lite 1.21 |
| Not Vulnerable: | |
Discussion
Cyboards PHP Lite Multiple Cross Site Scripting Vulnerabilities
Multiple cross site scripting vulnerabilities have been discovered in Cyboards PHP Lite. These issues occur due to insufficient validation of user supplied values.
It is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user. All code will be executed within the context of the website running Cyboards PHP Lite.
This issue could be exploited to steal a legitimate users cookie-based authentication credentials. Information gained in this manner could be later used to hijack a legitimate users web session.
Multiple cross site scripting vulnerabilities have been discovered in Cyboards PHP Lite. These issues occur due to insufficient validation of user supplied values.
It is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user. All code will be executed within the context of the website running Cyboards PHP Lite.
This issue could be exploited to steal a legitimate users cookie-based authentication credentials. Information gained in this manner could be later used to hijack a legitimate users web session.
Exploit / POC
Cyboards PHP Lite Multiple Cross Site Scripting Vulnerabilities
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Cyboards PHP Lite Multiple Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cyboards PHP Lite Multiple Cross Site Scripting Vulnerabilities
References:
References: