LedNews Post Script Code Injection Vulnerability
BID:7920
Info
LedNews Post Script Code Injection Vulnerability
| Bugtraq ID: | 7920 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0495 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery credited to "gilbert vilvoorde" <[email protected]>. |
| Vulnerable: |
Ledscripts.com LedNews 0.7 |
| Not Vulnerable: | |
Discussion
LedNews Post Script Code Injection Vulnerability
It has been reported that LedNews does not properly filter input from news posts. Because of this, it may be possible for an attacker to steal authentication cookies or perform other nefarious activities.
It has been reported that LedNews does not properly filter input from news posts. Because of this, it may be possible for an attacker to steal authentication cookies or perform other nefarious activities.
Solution / Fix
LedNews Post Script Code Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
LedNews Post Script Code Injection Vulnerability
References:
References:
- XSS Vulnerability in LedNews (CGI/Perl) v0.7 ("gilbert vilvoorde"
)