Mollensoft Software Enceladus Server Suite Guestbook HTML Injection Vulnerability
BID:7885
Info
Mollensoft Software Enceladus Server Suite Guestbook HTML Injection Vulnerability
| Bugtraq ID: | 7885 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2003 12:00AM |
| Updated: | Jun 12 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Ziv Kamir. |
| Vulnerable: |
Mollensoft Software Enceladus Server Suite 3.9.11 |
| Not Vulnerable: | |
Discussion
Mollensoft Software Enceladus Server Suite Guestbook HTML Injection Vulnerability
Enceladus Server Suite is prone to HTML injection attacks. The vulnerability exists in the Guestbook and is a result of insufficient sanitization of malicious HTML code from user-supplied input.
Exploitation could allow for attacks that steal cookie-based authentication credentials. Other attacks are also possible.
Enceladus Server Suite is prone to HTML injection attacks. The vulnerability exists in the Guestbook and is a result of insufficient sanitization of malicious HTML code from user-supplied input.
Exploitation could allow for attacks that steal cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
Mollensoft Software Enceladus Server Suite Guestbook HTML Injection Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Mollensoft Software Enceladus Server Suite Guestbook HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.