XMB Forum Member.PHP U2U Private Message HTML Injection Vulnerability
BID:7869
Info
XMB Forum Member.PHP U2U Private Message HTML Injection Vulnerability
| Bugtraq ID: | 7869 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2003 12:00AM |
| Updated: | Jun 10 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Joseph Polin <[email protected]>. |
| Vulnerable: |
XMB Forum 1.8 SP1 XMB Forum 1.8 |
| Not Vulnerable: | |
Discussion
XMB Forum Member.PHP U2U Private Message HTML Injection Vulnerability
XMB Forum 1.8 is a web based discussion forum.
A vulnerability has been reported for XMB Forum 1.8 which may make it prone to HTML injection attacks. The problem is said to occur while viewing U2U private messages.
Specifically, U2U private messages may not be sufficiently sanitized of malicious content. This may make it possible for an attacker to place HTML or script code within the message body of a private U2U message for another user.
XMB Forum 1.8 is a web based discussion forum.
A vulnerability has been reported for XMB Forum 1.8 which may make it prone to HTML injection attacks. The problem is said to occur while viewing U2U private messages.
Specifically, U2U private messages may not be sufficiently sanitized of malicious content. This may make it possible for an attacker to place HTML or script code within the message body of a private U2U message for another user.
Solution / Fix
XMB Forum Member.PHP U2U Private Message HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.