Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHProjekt Chatroom Text Submission HTML Injection Vulnerability

PHProjekt is prone to an HTML injection vulnerability in the Chatroom text submission form. The application fails to sanitize user-supplied input that is in turn displayed to all users of the chatroom.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.







 

Privacy Statement
Copyright 2009, SecurityFocus