11 lines
No EOL
723 B
Text
11 lines
No EOL
723 B
Text
source: https://www.securityfocus.com/bid/8930/info
|
|
|
|
It has been reported that E107 may be prone to a denial of service vulnerability. The issue has been reported to exist due to improper handling of user-supplied data in the form of HTML or script code to the 'Name:' field of Chatbox.php script. This issue may cause the software to behave in an unstable manner leading to a crash.
|
|
|
|
Successful exploitation of this issue may allow an attacker to cause the software to crash or hang.
|
|
|
|
It should be noted that although this vulnerability has been reported to affect E107 versions 0.545 and 0.603, other versions might also be affected.
|
|
|
|
In the Name inputbox of the Chatbox type:
|
|
|
|
<script = javascript> alert('DoS') <script> |