Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Xhawk.net Discussion BBCode IMG Tag Script Injection Vulnerability

The 'discussion' package from xhawk.net is prone to a script-injection vulnerability.

An attacker can use BBCode IMG tags to trigger this issue and execute arbitrary code in a user's browser.

Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for the theft of cookie-based authentication credentials. Other attacks are also possible.

Version 2.0 beta2 of 'discussion' is reportedly prone to this vulnerability.







 

Privacy Statement
Copyright 2009, SecurityFocus