Pod.Board New_Topic.PHP Multiple HTML Injection Vulnerabilities
BID:7936
Info
Pod.Board New_Topic.PHP Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 7936 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2003 12:00AM |
| Updated: | Jun 16 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Mask_NBTA <[email protected]>. |
| Vulnerable: |
planetinsanity.de pod.board 1.1 |
| Not Vulnerable: | |
Discussion
Pod.Board New_Topic.PHP Multiple HTML Injection Vulnerabilities
The pod.board 'new_topic.php' script does not sufficiently sanitize data supplied via URI parameters and input fields, making it prone to HMTL injection attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code.
Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.
The pod.board 'new_topic.php' script does not sufficiently sanitize data supplied via URI parameters and input fields, making it prone to HMTL injection attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code.
Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.
Solution / Fix
Pod.Board New_Topic.PHP Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.