PY-Livredor index.php HTML Injection Vulnerability
BID:6997
Info
PY-Livredor index.php HTML Injection Vulnerability
| Bugtraq ID: | 6997 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2003 12:00AM |
| Updated: | Mar 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Gregory Le Bras | Security Corporation". |
| Vulnerable: |
PY-Livredor PY-Livredor 1.0 |
| Not Vulnerable: | |
Discussion
PY-Livredor index.php HTML Injection Vulnerability
PY-Livredor does not adequately filter HTML tags from various fields. This may enable an attacker to inject arbitrary HTML code into pages that are generated by the guestbook.
The attacker's code may be executed in the web client of users who view the pages generated by the guestbook, in the security context of the website hosting the software.
Attackers may potentially exploit this issue to hijack web content or to steal cookie-based authentication credentials.
PY-Livredor does not adequately filter HTML tags from various fields. This may enable an attacker to inject arbitrary HTML code into pages that are generated by the guestbook.
The attacker's code may be executed in the web client of users who view the pages generated by the guestbook, in the security context of the website hosting the software.
Attackers may potentially exploit this issue to hijack web content or to steal cookie-based authentication credentials.
Exploit / POC
PY-Livredor index.php HTML Injection Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
PY-Livredor index.php HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PY-Livredor index.php HTML Injection Vulnerability
References:
References:
- Cross Site Scripting & Script Injection Vulnerability in PY-Livredor ("Gregory Le Bras | Security Corporation")