Exploit ShoutBox 1.2 - 'Form' HTML Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21668
Проверка EDB
  1. Пройдено
Автор
DELUSION
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2002-1429
Дата публикации
2002-07-29
Код:
source: https://www.securityfocus.com/bid/5354/info

shoutBOX does not sufficiently sanitize HTML tags from input supplied via form fields. Attackers may exploit this lack of input validation to inject arbitrary HTML and script code into pages that are generated by the script. This may result in execution of attacker-supplied code in the web client of a user who visits such a page. HTML and script code will be executed in the security context of the site hosting the software. 

In the Site URL text box, type in:

"></a><html code goes here><a href="
 
Источник
www.exploit-db.com

Похожие темы