PHPLinks Search HTML Injection Vulnerability
BID:6633
Info
PHPLinks Search HTML Injection Vulnerability
| Bugtraq ID: | 6633 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2003 12:00AM |
| Updated: | Jan 16 2003 12:00AM |
| Credit: | Discovery of this issue is credited to JeiAr <[email protected]>. |
| Vulnerable: |
phpLinks phpLinks 2.1.2 |
| Not Vulnerable: | |
Discussion
PHPLinks Search HTML Injection Vulnerability
phpLinks is prone to HTML injection due to a vulnerability in the search feature.
Search queries are not sufficiently sanitized of HTML and script code. These search queries may potentially be displayed to other users when the most popular searches are viewed. If an attacker includes malicious HTML or script code in these queries, it is possible that the attacker-supplied code may be rendered in the web client software of other users.
phpLinks is prone to HTML injection due to a vulnerability in the search feature.
Search queries are not sufficiently sanitized of HTML and script code. These search queries may potentially be displayed to other users when the most popular searches are viewed. If an attacker includes malicious HTML or script code in these queries, it is possible that the attacker-supplied code may be rendered in the web client software of other users.
Exploit / POC
PHPLinks Search HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PHPLinks Search HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.