Verity K2 Toolkit Query Builder Search Script Cross-Site Scripting Vulnerability
BID:8074
Info
Verity K2 Toolkit Query Builder Search Script Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8074 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2003 12:00AM |
| Updated: | Jul 02 2003 12:00AM |
| Credit: | Discovery credited to SSR Team. |
| Vulnerable: |
Verity Inc. K2 Toolkit 2.20 |
| Not Vulnerable: | |
Discussion
Verity K2 Toolkit Query Builder Search Script Cross-Site Scripting Vulnerability
It has been reported that the K2 Toolkit does not sufficiently sanitize input by users. Because of this, it may be possible for an attacker to launch an attack that results in the execution of hostile HTML or script code in the browsers of users that have loaded a malicious link created by the attacker.
It has been reported that the K2 Toolkit does not sufficiently sanitize input by users. Because of this, it may be possible for an attacker to launch an attack that results in the execution of hostile HTML or script code in the browsers of users that have loaded a malicious link created by the attacker.
Solution / Fix
Verity K2 Toolkit Query Builder Search Script Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Verity K2 Toolkit Query Builder Search Script Cross-Site Scripting Vulnerability
References:
References:
- Company Homepage (Verity)