newsPHP Comment Feature HTML Injection Vulnerability
BID:7834
Info
newsPHP Comment Feature HTML Injection Vulnerability
| Bugtraq ID: | 7834 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2003 12:00AM |
| Updated: | Jun 06 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to morning_wood [email protected]. |
| Vulnerable: |
newsPHP newsPHP |
| Not Vulnerable: | |
Discussion
newsPHP Comment Feature HTML Injection Vulnerability
newsPHP is prone to HTML injection attacks. The vulnerability exists due to insufficient sanitization of malicious HTML code in user-supplied comments.
HTML and script code may be echoed back when an existing user views any malicious comments. It is possible that code injected through this issue could be displayed and rendered by other newsPHP forum users.
newsPHP is prone to HTML injection attacks. The vulnerability exists due to insufficient sanitization of malicious HTML code in user-supplied comments.
HTML and script code may be echoed back when an existing user views any malicious comments. It is possible that code injected through this issue could be displayed and rendered by other newsPHP forum users.
Solution / Fix
newsPHP Comment Feature HTML Injection Vulnerability
Solution:
The vendor has stated that this issue has been fixed. Users are advised to contact the vendor for further details.
Solution:
The vendor has stated that this issue has been fixed. Users are advised to contact the vendor for further details.
References
newsPHP Comment Feature HTML Injection Vulnerability
References:
References:
- EXPL-A-2003-003 exploitlabs.com Advisory 003 (morning_wood [email protected])
- newsPHP (newsPHP)