PHP-Nuke Splatt Forum 4.0 Module - HTML Injection

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1053860 漏洞类型
发布时间 2003-05-01 更新时间 2003-05-01
漏洞平台 PHP CVSS评分 N/A

A problem with Splatt Forum could allow remote users to execute arbitrary code in the context of the web site running the Splatt Forum module. The problem occurs due to the lack of sanitization performed on character representations of HTML tags.

As a result, a malicious user may be able to submit a post to the vulnerable site containing embedded script code. This code would be executed by a user's browser in the context of the site.

This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software. The attacker may hijack the session of the legitimate by using cookie-based authentication credentials. Other attacks are also possible.

It should be noted that although this vulnerability has been reported to affect Splatt Forum version 4.0, previous versions may also be affected. 

Typical text here <script>alert(document.cookie);</script> additional text here.