DCForum+ Subject Field HTML Injection Vulnerability
BID:8384
Info
DCForum+ Subject Field HTML Injection Vulnerability
| Bugtraq ID: | 8384 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2003 12:00AM |
| Updated: | Aug 11 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to G00db0y <[email protected]>. |
| Vulnerable: |
DC Scripts DCForum+ 1.2 |
| Not Vulnerable: | |
Discussion
DCForum+ Subject Field HTML Injection Vulnerability
DCForum+ is prone to an HTML injection vulnerability. An attacker may exploit this issue by including hostile HTML and script code in the subject field of posts to the bulletin board. This is because the script that processes posts does not sufficiently sanitize user input, allowing attackers to embed HTML and script commands within the post. This code may be rendered in the web browser of a user who views these areas of the site. This would occur in the security context of the site hosting DCForum+.
DCForum+ is prone to an HTML injection vulnerability. An attacker may exploit this issue by including hostile HTML and script code in the subject field of posts to the bulletin board. This is because the script that processes posts does not sufficiently sanitize user input, allowing attackers to embed HTML and script commands within the post. This code may be rendered in the web browser of a user who views these areas of the site. This would occur in the security context of the site hosting DCForum+.
Solution / Fix
DCForum+ Subject Field HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DCForum+ Subject Field HTML Injection Vulnerability
References:
References:
- DCScripts DCForum Homepage (DCScripts)
- ZH2003-21SA (security advisory): DcForum+ XSS Vulnerability (G00db0y
)