Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  SMF "index.
php?action=pm" Cross Site-Scripting

  Paypal Subscription Manager Multiple HTML Injections

  Login Manager Multiple HTML Injections

  a-forum  xss

From:Hackers Center Security Group <DoZ_(at)_hackerscenter.com>
Date:20 января 2007 г.
Subject:MyShoutBox Multiple Cross-Site Scripting Vulnerability

A Shoutbox is a new interaction possiblity for visitors to your site! With a Shoutbox, site visitors develop a durable, personal relationship with your homepage.  Customer relations is indispensable for today's websites.



Hackers Center Security Group (http://www.hackerscenter.com)

Credit: Doz


Risk: Low
vendor: http://www.myshoutbox.com/


Class: Cross-Site Scripting
Remote: Yes


Version: Current ShoutBox
Exploit: An attacker can exploit these issues via a web client.


An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks like shoutbox defacement. The XSS lies in the Shoutbox Form. Proper filtering is needed to secure the application.

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server