Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Thatware Cross-Site Scripting Vulnerability

Thatware is a bulletin board, discussion and portal framework. Thatware is very similar to Slascode, which is behind the popular Slashdot page.

A cross site scripting vulnerability exists in Thatware. By constructing a URL to a vulnerable site, an attacker may insert script commands into the displayed page. If a user of the Thatware system follows such a link, the script will execute in the context of the Thatware page. This may lead to the compromise of that user's Thatware account, through the theft of cookie data.







 

Privacy Statement
Copyright 2009, SecurityFocus