ZeroBoard Multiple Remote Script Injection And Cross-Site Scripting Vulnerabilities

Multiple script injection and cross-site scripting vulnerabilities reportedly affect ZeroBoard. These issues are due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage these issues to execute arbitrary server-side scripts and carry out cross-site scripting attacks against unsuspecting users. This may facilitate a compromise of the host computer, as well as theft of cookie-based authentication credentials. Other attacks are also possible.


 

Privacy Statement
Copyright 2010, SecurityFocus