Web Wiz Forums Multiple Cross-Site Scripting Vulnerabilities
BID:8866
Info
Web Wiz Forums Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 8866 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2003 12:00AM |
| Updated: | Oct 21 2003 12:00AM |
| Credit: | These vulnerabilities were reported by HEX <[email protected]>. |
| Vulnerable: |
Web Wiz Forums Web Wiz Forums 7.0 1 |
| Not Vulnerable: |
Web Wiz Forums Web Wiz Forums 7.5 |
Discussion
Web Wiz Forums Multiple Cross-Site Scripting Vulnerabilities
Web Wiz Forums has been reported prone to cross-site scripting attacks. The problems occur in a number of .asp script files. As a result, an attacker who constructs a malicious URI request may be capable of rendering arbitrary script code within the browser of a victim user.
New information has been made available by the vendor stating that one of the affected script files reported (forum_members.asp) does not exist. As such, some of the reported cross-site scripting issues may not exist.
Web Wiz Forums has been reported prone to cross-site scripting attacks. The problems occur in a number of .asp script files. As a result, an attacker who constructs a malicious URI request may be capable of rendering arbitrary script code within the browser of a victim user.
New information has been made available by the vendor stating that one of the affected script files reported (forum_members.asp) does not exist. As such, some of the reported cross-site scripting issues may not exist.
Exploit / POC
Web Wiz Forums Multiple Cross-Site Scripting Vulnerabilities
No exploit required.
No exploit required.
Solution / Fix
Web Wiz Forums Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor has stated that what cross-site scripting issues did exist in Web Wiz Forums do not affected version 7.5. As such, users are advised to upgrade to this version as soon as possible.
Web Wiz Forums 7.5 can be obtained by visting the referenced vendor site.
Solution:
The vendor has stated that what cross-site scripting issues did exist in Web Wiz Forums do not affected version 7.5. As such, users are advised to upgrade to this version as soon as possible.
Web Wiz Forums 7.5 can be obtained by visting the referenced vendor site.
References
Web Wiz Forums Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Web Wiz Forums Homepage (Web Wiz)
- Re: Web Wiz Forums ver. 7.01 (
)