NetWin DBabble Cross-Site Scripting Vulnerability
BID:8637
Info
NetWin DBabble Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8637 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2003 12:00AM |
| Updated: | Sep 16 2003 12:00AM |
| Credit: | Discovery credited to dr_insane. |
| Vulnerable: |
NetWin DBabble 2.5 i |
| Not Vulnerable: | |
Discussion
NetWin DBabble Cross-Site Scripting Vulnerability
A cross-site scripting problem has been reported in NetWin DBabble. This could make it possible for an attacker to potentially execute code in the security context of a site using the vulnerable software. This could be exploited by enticing a user to follow a malicious link to a site hosting the software.
A cross-site scripting problem has been reported in NetWin DBabble. This could make it possible for an attacker to potentially execute code in the security context of a site using the vulnerable software. This could be exploited by enticing a user to follow a malicious link to a site hosting the software.
Exploit / POC
NetWin DBabble Cross-Site Scripting Vulnerability
The following proof-of-concept has been made available:
http://www.example.com/dbabble?cmd="><evil_script>
The following proof-of-concept has been made available:
http://www.example.com/dbabble?cmd="><evil_script>
Solution / Fix
NetWin DBabble Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.