|
|
|
![]() |
Vulnerability Note VU#255915WebBoard does not adequately validate user input thereby permitting arbitrary JavaScript executionOverviewWebBoard does not adequately validate user input, allowing attackers to execute arbitrary JavaScript code on other WebBoard users' systems.I. DescriptionWebBoard is a web application which includes a real-time chat server, using JavaScript alerts to display messages received by other users. WebBoard does not adequately filter messages sent through the chat server, allowing attackers to execute arbitrary JavaScript code on other users' systems.II. ImpactAttackers can execute arbitrary JavaScript code on other WebBoard client users' systems.III. SolutionUpgradeUpgrade to WebBoard version 4.2, available at:
Referenceshttp://www.securityfocus.com/bid/2814
Thanks to Helmuth Antholzer for reporting this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||