IndyNews HTML Injection Vulnerability
BID:6858
Info
IndyNews HTML Injection Vulnerability
| Bugtraq ID: | 6858 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 14 2003 12:00AM |
| Updated: | Feb 14 2003 12:00AM |
| Credit: | he discovery of this vulnerability has been credited to Elisa Manara <[email protected]>. |
| Vulnerable: |
IndyNews IndyNews 0 |
| Not Vulnerable: | |
Discussion
IndyNews HTML Injection Vulnerability
A vulnerability has been discovered in the IndyNews module available for PHP-Nuke. Due to insufficient sanitization of some HTML tags it is possible to embed HTML code within the 'alt' tags of a news article. When the news article is viewed by an unsuspecting user the embedded code will be executed within the context of the site visited.
The precise technical details regarding this vulnerability are currently unknown. This BID will be updated accordingly as more information is made available.
A vulnerability has been discovered in the IndyNews module available for PHP-Nuke. Due to insufficient sanitization of some HTML tags it is possible to embed HTML code within the 'alt' tags of a news article. When the news article is viewed by an unsuspecting user the embedded code will be executed within the context of the site visited.
The precise technical details regarding this vulnerability are currently unknown. This BID will be updated accordingly as more information is made available.
Exploit / POC
IndyNews HTML Injection Vulnerability
No exploit is required.
No exploit is required.
References
IndyNews HTML Injection Vulnerability
References:
References:
- IndyNews - PhpNuke module: several problems (Elisa Manara
)