10 lines
No EOL
598 B
Text
10 lines
No EOL
598 B
Text
source: https://www.securityfocus.com/bid/16395/info
|
|
|
|
My Little Homepage Web log, guestbook, and forum are prone to a script injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
|
|
|
|
Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. Other attacks are also possible.
|
|
|
|
BBCode example have been provided:
|
|
|
|
[link=javascript:alert(123)]Link[/link]
|
|
[link]javascript:alert(123)[/link] |