Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

TYPO3 WEC Discussion Forum Security Bypass and Multiple Cross Site Scripting Vulnerabilities

WEC Discussion Forum is prone to a security-bypass issue and multiple cross-site scripting issues because it fails to sufficiently sanitize user-supplied data.

An attacker may exploit the security-bypass vulnerability to upload arbitrary files and execute script code in the context of the webserver process.

The attacker may also leverage the cross-site scripting issues to execute script code in an unsuspecting user's browser or to steal cookie-based authentication credentials; other attacks are also possible.

These issues affect versions prior to WEC Discussion Forum 1.6.3.







 

Privacy Statement
Copyright 2009, SecurityFocus