WebBBS Guestbook HTML Injection Vulnerability
BID:8052
Info
WebBBS Guestbook HTML Injection Vulnerability
| Bugtraq ID: | 8052 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2003 12:00AM |
| Updated: | Jun 27 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Thierry LAVIE <[email protected]>. |
| Vulnerable: |
Mike Bryeans WebBBS Pro 1.18 |
| Not Vulnerable: | |
Discussion
WebBBS Guestbook HTML Injection Vulnerability
A HTML injection vulnerability has been reported for WebBBS. The vulnerability exists as a result of insufficient sanitization of user-supplied data into guestbook entries.
Exploitation could permit an attacker to steal cookie-based authentication credentials or launch other attacks.
A HTML injection vulnerability has been reported for WebBBS. The vulnerability exists as a result of insufficient sanitization of user-supplied data into guestbook entries.
Exploitation could permit an attacker to steal cookie-based authentication credentials or launch other attacks.