E107 Chatbox.php Denial of Service Vulnerability
BID:8930
Info
E107 Chatbox.php Denial of Service Vulnerability
| Bugtraq ID: | 8930 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2003 12:00AM |
| Updated: | Oct 29 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Blademaster <[email protected]>. |
| Vulnerable: |
e107 e107 website system 0.603 e107 e107 website system 0.545 |
| Not Vulnerable: | |
Discussion
Exploit / POC
E107 Chatbox.php Denial of Service Vulnerability
The following proof of concept has been provided:
In the Name inputbox of the Chatbox type:
<script = javascript> alert('DoS') <script>
The following proof of concept has been provided:
In the Name inputbox of the Chatbox type:
<script = javascript> alert('DoS') <script>
Solution / Fix
E107 Chatbox.php Denial of Service Vulnerability
Solution:
The vendor has supplied a fix to address this issue:
e107 e107 website system 0.545
e107 e107 website system 0.603
Solution:
The vendor has supplied a fix to address this issue:
e107 e107 website system 0.545
-
e107.org class2.zip
http://e107.org/e107_files/misc/class2.zip
e107 e107 website system 0.603
-
e107.org class2.zip
http://e107.org/e107_files/misc/class2.zip
References
E107 Chatbox.php Denial of Service Vulnerability
References:
References:
- e107 website system Homepage (e107.org)