XMB Forum Member.PHP Location Field HTML Injection Vulnerability
BID:7870
Info
XMB Forum Member.PHP Location Field HTML Injection Vulnerability
| Bugtraq ID: | 7870 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2003 12:00AM |
| Updated: | Jun 10 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Joseph Polin <[email protected]>. |
| Vulnerable: |
XMB Forum 1.8 SP1 XMB Forum 1.8 |
| Not Vulnerable: | |
Discussion
XMB Forum Member.PHP Location Field HTML Injection Vulnerability
A vulnerability has been reported in XMB Forum that may result in HTML injection. The vulnerability occurs because XMB Forum fails to sufficiently sanitize user-supplied input that is used for the 'Location' field in a registered users personal information page. Other fields may also be similarly affected.
Due to this condition, a malicious user may be able to insert malicious HTML or script code, as 'Location' field data. Any attacker-supplied code will be interpreted in a victim user's web browser in the security context of the site hosting the software.
A vulnerability has been reported in XMB Forum that may result in HTML injection. The vulnerability occurs because XMB Forum fails to sufficiently sanitize user-supplied input that is used for the 'Location' field in a registered users personal information page. Other fields may also be similarly affected.
Due to this condition, a malicious user may be able to insert malicious HTML or script code, as 'Location' field data. Any attacker-supplied code will be interpreted in a victim user's web browser in the security context of the site hosting the software.
References
XMB Forum Member.PHP Location Field HTML Injection Vulnerability
References:
References:
- XMB Forum Home Page (The XMB Group)