SecurityFocus BUGTRAQ Mailing List: BugTraqLink Number One Link Number One Link Number Two Link Number Two Link Number One Link Number One Link Number Two Link Number Two Entire Site Advisories Calendar Columnists Elsewhere Guest Feature Infocus Library Links Mailing Lists (all) -- BUGTRAQ -- FOCUS-IDS -- FOCUS-IH -- FOCUS-LINUX -- FOCUS-MS -- FOCUS-SUN -- FOCUS-VIRUS -- FORENSICS -- INCIDENTS -- PEN-TEST -- SEC JOBS -- SF NEWS -- VULN-DEV News Products Services Tools Vulns BUGTRAQ ARCHIVE [ Message Index ] [ Thread Index ][ Reply ] [ prev Msg by Date ][ next Msg by Date ] To: BugTraq Subject: Comment Board XSS Vulnerability Date: Sep 24 2003 8:43PM Author: Bahaa Naamneh Message-ID: <20030924204320.2399.qmail@sf-www1-symnsj.securityfocus.com> Comment Board XSS Vulnerability Published: 24 September 2003 Released: 24 September 2003 Affected Systems: Comment Board Vendor: http://www.ymonda.co.uk Issue: Remote attackers can inject XSS script. Description: ============ "Comment Board works straight away with little or no configuration required and provides a wealth of exciting features that will keep your web site visitors coming back for more. Check out our online demo and try a free downloadable version now." Details: ======== It's possibile to inject XSS script in the Topic Title, Name and Message fields. Examples: "><script> this code will hide every thing after it including the the board topics if any attacker write it in the topic title. <script>windows.open("URL");</script> this code will open a new window when the board loaded. Solution: ========= The vendor has been contacted and a patch is not yet produced. Suggestions: ============ Filter all variables. Discovered by / credit: ======================= Bahaa Naamneh b_naamneh hotmail com http://www.bsecurity.tk Want to link to this message? Use this URL: Disclaimer, Terms & Conditions About this List Featured Lists: ARIS Users bugtraq bugtraq-es bugtraq-french NEW bugtraq-jp firewalls focus-ids focus-ih focus-linux focus-ms focus-sun focus-unix-other focus-virus forensics forensics-es honeypots incidents libnet pen-test secevents secpapers secprog sectools secureshell security-basics security-management NEW securityjobs vpn vuln-dev webappsec Newsletters: sf-news ms-secnews linux-secnews [ more . . . ] Privacy Statement Copyright © 1999-2003 SecurityFocus