WWWBoard HTML Injection Vulnerability
BID:6918
Info
WWWBoard HTML Injection Vulnerability
| Bugtraq ID: | 6918 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2003 12:00AM |
| Updated: | Feb 23 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "Grégory" Le Bras <[email protected]>. |
| Vulnerable: |
Matt Wright WWWBoard 2.0 Alpha 2.1 Matt Wright WWWBoard 2.0 Alpha 2 |
| Not Vulnerable: | |
Discussion
WWWBoard HTML Injection Vulnerability
A vulnerability has been discovered in WWWBoard version 2.0A2.1 and earlier. Due to insufficient sanitization of user-supplied forum input, attackers may embed malicious script code or HTML into forum posts.
When a malicious post is viewed by another user, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the software.
A vulnerability has been discovered in WWWBoard version 2.0A2.1 and earlier. Due to insufficient sanitization of user-supplied forum input, attackers may embed malicious script code or HTML into forum posts.
When a malicious post is viewed by another user, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the software.
Exploit / POC
WWWBoard HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
WWWBoard HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WWWBoard HTML Injection Vulnerability
References:
References:
- WWWBoard Homepage (Matt Wright
) - [SCSA-007] Cross Site Scripting Vulnerabilities in WWWBoard ("Grégory" Le Bras
)