Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Simple Machines Forum Size Tag HTML Injection Vulnerability

It has been reported that Simple Machines Forum (SMF) may be prone to an HTML injection vulnerability that may allow an attacker to execute arbitrary HTML or script code in a user's browser. The issue exists due to insufficient sanitization of user-supplied input via the font size attribute.

Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.







 

Privacy Statement
Copyright 2009, SecurityFocus