IdealBB Error.ASP Cross-Site Scripting Vulnerability
BID:8360
Info
IdealBB Error.ASP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8360 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2003 12:00AM |
| Updated: | Aug 07 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to G00db0y <[email protected]>. |
| Vulnerable: |
Ideal Science IdealBB 1.4.9 Beta |
| Not Vulnerable: | |
Discussion
IdealBB Error.ASP Cross-Site Scripting Vulnerability
IdealBB error.asp page has been reported prone to a cross-site scripting vulnerability.
The issue presents itself due to a lack of sufficient sanitization performed by functions in the error.asp script on user-influenced URI parameters. This vulnerability may be exploited to permit the theft of cookie authentication credentials if a malicious link is followed. Other attacks may also be possible.
IdealBB error.asp page has been reported prone to a cross-site scripting vulnerability.
The issue presents itself due to a lack of sufficient sanitization performed by functions in the error.asp script on user-influenced URI parameters. This vulnerability may be exploited to permit the theft of cookie authentication credentials if a malicious link is followed. Other attacks may also be possible.
References
IdealBB Error.ASP Cross-Site Scripting Vulnerability
References:
References:
- Ideal Bulletin Board Homepage (Ideal Science)