Zope ExampledbBrowseReport Description Field HMTL Injection Vulnerability
BID:8001
Info
Zope ExampledbBrowseReport Description Field HMTL Injection Vulnerability
| Bugtraq ID: | 8001 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2003 12:00AM |
| Updated: | Jun 20 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Donnie Werner. |
| Vulnerable: |
Zope Zope 2.6.1 Zope Zope 2.5.1 |
| Not Vulnerable: | |
Discussion
Zope ExampledbBrowseReport Description Field HMTL Injection Vulnerability
It has been reported that Zope ExampledbBrowseReport example script suffers from an HTML injection vulnerability. The problem is said to occur due to insufficient input validation of user-supplied form data.
All script code will be interpreted by the browsers of other Zope users, who view the affected page, within the context of the site hosting the affected script.
It has been reported that Zope ExampledbBrowseReport example script suffers from an HTML injection vulnerability. The problem is said to occur due to insufficient input validation of user-supplied form data.
All script code will be interpreted by the browsers of other Zope users, who view the affected page, within the context of the site hosting the affected script.
References
Zope ExampledbBrowseReport Description Field HMTL Injection Vulnerability
References:
References:
- Re: [Zope-dev] weak examples, weak exploits (Jamie Heilman
) - Welcome to Zope.org (Zope)
- Zope Vulnerabilities (Donnie Werner)