MiniBB Profile Website Name HTML Injection Vulnerability
BID:9310
Info
MiniBB Profile Website Name HTML Injection Vulnerability
| Bugtraq ID: | 9310 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2003 12:00AM |
| Updated: | Dec 29 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Chintan Trivedi. |
| Vulnerable: |
MiniBB MiniBB 1.7 MiniBB MiniBB 1.6 MiniBB MiniBB 1.5 MiniBB MiniBB 1.2 |
| Not Vulnerable: | |
Discussion
MiniBB Profile Website Name HTML Injection Vulnerability
miniBB is prone to an HTML injection vulnerability. This issue could permit registered users to inject hostile HTML and script code into the 'website name' field of their user profile, which would be rendered by other web users when the user profile is viewed.
This could be exploited to steal cookie-based authentication credentials. It is also possible to use this type of vulnerability as an attack vector to exploit latent browser security flaws.
miniBB is prone to an HTML injection vulnerability. This issue could permit registered users to inject hostile HTML and script code into the 'website name' field of their user profile, which would be rendered by other web users when the user profile is viewed.
This could be exploited to steal cookie-based authentication credentials. It is also possible to use this type of vulnerability as an attack vector to exploit latent browser security flaws.
Exploit / POC
MiniBB Profile Website Name HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
MiniBB Profile Website Name HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MiniBB Profile Website Name HTML Injection Vulnerability
References:
References:
- miniBB Homepage (miniBB)
- Cross Site Scripting vulnerability in miniBB 1.7 (latest) and earlier (Chintan Trivedi
)