IdealBB HTML Injection Vulnerability
BID:8480
Info
IdealBB HTML Injection Vulnerability
| Bugtraq ID: | 8480 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2003 12:00AM |
| Updated: | Aug 23 2003 12:00AM |
| Credit: | Discovery is credited to Scott M <[email protected]>. |
| Vulnerable: |
Ideal Science IdealBB 1.4.9 Beta |
| Not Vulnerable: | |
Discussion
IdealBB HTML Injection Vulnerability
IdealBB is prone to an HTML injection vulnerability. This could permit remote attackers to inject malicious HTML and script code into board messages. The attacker's code may be rendered in the web browser of the user viewing the malicious message.
IdealBB is prone to an HTML injection vulnerability. This could permit remote attackers to inject malicious HTML and script code into board messages. The attacker's code may be rendered in the web browser of the user viewing the malicious message.
Exploit / POC
IdealBB HTML Injection Vulnerability
The following proof of concept was provided by Scott M <[email protected]>:
<a href="http://www.google.com" onclick="javascript:alert(document.cookie);">Google</a>
The following proof of concept was provided by Scott M <[email protected]>:
<a href="http://www.google.com" onclick="javascript:alert(document.cookie);">Google</a>
Solution / Fix
IdealBB HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.