Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PScript PForum User Profile HTML Injection Vulnerability

PScript PForum is reported prone to a HTML injection vulnerability. The vulnerability presents itself due to a lack of sufficient sanitization performed on data submitted through input fields of the PForum user profile form.

This could be exploited to steal cookie-based authentication credentials. It is also possible to use this type of vulnerability as an attack vector to exploit latent browser security flaws.







 

Privacy Statement
Copyright 2009, SecurityFocus