EZ Publish Index.PHP IMG Tag Cross Site Scripting Vulnerability
BID:7616
Info
EZ Publish Index.PHP IMG Tag Cross Site Scripting Vulnerability
| Bugtraq ID: | 7616 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2003 12:00AM |
| Updated: | May 16 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Ferruh Mavituna" <[email protected]>. |
| Vulnerable: |
eZ Systems eZ publish 2.2 |
| Not Vulnerable: |
eZ Systems eZ publish 3.0 |
Discussion
EZ Publish Index.PHP IMG Tag Cross Site Scripting Vulnerability
A cross-site scripting vulnerability has been reported for eZ publish. Specifically, eZ publish does not sufficiently sanitize user-supplied input supplied to the 'index.php' script.
This may allow for theft of cookie-based authentication credentials and other attacks.
A cross-site scripting vulnerability has been reported for eZ publish. Specifically, eZ publish does not sufficiently sanitize user-supplied input supplied to the 'index.php' script.
This may allow for theft of cookie-based authentication credentials and other attacks.