CSO Lanifex Outreach Project Tool HTML Injection Vulnerability
BID:6631
Info
CSO Lanifex Outreach Project Tool HTML Injection Vulnerability
| Bugtraq ID: | 6631 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2003 12:00AM |
| Updated: | Jan 16 2003 12:00AM |
| Credit: | Vulnerability discovery credited to Martin Eiszner <[email protected]>. |
| Vulnerable: |
CSO Lanifex Outreach Project Tool 0.946 b |
| Not Vulnerable: | |
Discussion
CSO Lanifex Outreach Project Tool HTML Injection Vulnerability
It has been reported that OPT does not properly filter input from remote users. Because of this, it is possible for a remote user to inject arbitrary HTML or script code into the site that will be executed in the security context of the OPT site.
It has been reported that OPT does not properly filter input from remote users. Because of this, it is possible for a remote user to inject arbitrary HTML or script code into the site that will be executed in the security context of the OPT site.
Exploit / POC
CSO Lanifex Outreach Project Tool HTML Injection Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
CSO Lanifex Outreach Project Tool HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CSO Lanifex Outreach Project Tool HTML Injection Vulnerability
References:
References:
- Outreach Project Tool (CSO Lanifex)
- Outreach Project Tool (Martin Eiszner
)