exploit-db-mirror/platforms/asp/webapps/24214.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

8 lines
No EOL
524 B
Text
Executable file

source: http://www.securityfocus.com/bid/10555/info
A vulnerability exists in the Web Wiz Forums software that may allow a remote user to launch cross-site scripting attacks. The problem is reported to exist due to improper sanitizing of user-supplied data passed to the 'registration_rules.asp' script.
An attacker can exploit this issue to steal cookie authentication credentials, or perform other types of attacks.
registration_rules.asp?FID=%22%3E%3Cscript%3Ealert%28%27Vulnerable%2520%21%2
7%29%3C%2Fscript%3E