pMachine Search Module Cross-Site Scripting Vulnerability
BID:7981
Info
pMachine Search Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7981 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2003 12:00AM |
| Updated: | Jun 19 2003 12:00AM |
| Credit: | This vulnerability was reported by "Lorenzo Hernandez Garcia-Hierro" <[email protected]>. |
| Vulnerable: |
PMachine PMachine 2.2.1 PMachine PMachine 2.2 PMachine PMachine 2.1 PMachine PMachine 2.0 PMachine PMachine 1.0 |
| Not Vulnerable: | |
Discussion
pMachine Search Module Cross-Site Scripting Vulnerability
Reportedly, pMachine is vulnerable to a cross-site scripting attack. The vulnerability is present in the search module. The issue presents itself likely due to insufficient sanitization performed on user-supplied data that is passed as the query to the affected module.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link. Attacker-supplied code passed as the keywords URI parameter may execute within the context of the site hosting the vulnerable software when the malicious link is visited.
Reportedly, pMachine is vulnerable to a cross-site scripting attack. The vulnerability is present in the search module. The issue presents itself likely due to insufficient sanitization performed on user-supplied data that is passed as the query to the affected module.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link. Attacker-supplied code passed as the keywords URI parameter may execute within the context of the site hosting the vulnerable software when the malicious link is visited.