WackoWiki TextSearch Cross-Site Scripting Vulnerability

It is reported that WackoWiki is susceptible to a cross-site scripting vulnerability in its textsearch form. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated web content.

Exploitation of this vulnerability may allow for theft of cookie-based authentication credentials and other attacks.


 

Privacy Statement
Copyright 2010, SecurityFocus