10 lines
No EOL
808 B
Text
10 lines
No EOL
808 B
Text
source: https://www.securityfocus.com/bid/8626/info
|
|
|
|
Nokia Electronic Documentation (NED) has been reported prone to a cross-site scripting vulnerability. The issue has been conjectured to present itself due to a lack of sufficient sanitization performed on user supplied data.
|
|
|
|
A remote attacker may exploit this issue by enticing a target user to follow a malicious link to the affected Nokia Electronic Documentation site, which contains embedded HTML and script code. The attacker-supplied code would potentially be rendered in the user's browser when the link is followed.
|
|
|
|
It should be noted that although this vulnerability has been reported to affect Nokia Electronic Documentation version 5.0, previous versions might also be affected.
|
|
|
|
|
|
http://www.example.com/docs/<script>alert('@stake');</script> |