Owl Intranet Engine Search Cross Site Scripting Vulnerability
BID:7644
Info
Owl Intranet Engine Search Cross Site Scripting Vulnerability
| Bugtraq ID: | 7644 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2003 12:00AM |
| Updated: | May 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to methodic <[email protected]>. |
| Vulnerable: |
Owl Owl Intranet Engine 0.71 Owl Owl Intranet Engine 0.7 Owl Owl Intranet Engine 0.6 |
| Not Vulnerable: |
Owl Owl Intranet Engine 0.72 |
Discussion
Owl Intranet Engine Search Cross Site Scripting Vulnerability
Owl Intranet Engine has been reported prone to a Cross-Site Scripting vulnerability.
It has been reported that search queries are not sufficiently sanitized of HTML and script code, an attacker may supply arbitrary HTML code as a search query submitted to the vulnerable site.
Owl version 0.71 and previous have been reported vulnerable.
Owl Intranet Engine has been reported prone to a Cross-Site Scripting vulnerability.
It has been reported that search queries are not sufficiently sanitized of HTML and script code, an attacker may supply arbitrary HTML code as a search query submitted to the vulnerable site.
Owl version 0.71 and previous have been reported vulnerable.
Exploit / POC
Owl Intranet Engine Search Cross Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
References
Owl Intranet Engine Search Cross Site Scripting Vulnerability
References:
References: