SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#674542

Powie's PSCRIPT Forum fails to filter user posts

Overview

Powie's PSCRIPT Forum fails to properly sanitize user input, which allows an attacker to create a user profile that can execute arbitrary scripts in a victim's web browser when the victim views the profile.

I. Description

Powie's PSCRIPT Forum is an online forum application written in PHP. The application allows users to set up a user profile which may be viewed by other users. A failure to filter input in two fields of the user profile section may permit a malicious user to post HTML/script that will be interpreted by a victim's client.

II. Impact

A malicious user can execute arbitrary HTML/script in the context of the vulnerable web site. If this vulnerability is exploited, a user may be tricked into exposing sensitive information, allowing an attacker to gather information such as passwords and credit card numbers. Information stored in cookies may also be stolen or corrupted.

III. Solution

This issue is resolved in version 1.26 of the forum, available from the pscript.de download page.

Systems Affected

VendorStatusDate NotifiedDate Updated
PScript.deVulnerable18-Aug-2004

References


http://www.pscript.de/news/index.php
http://www.osvdb.org/displayvuln.php?osvdb_id=8985
http://www.securityfocus.com/archive/1/371782
http://secunia.com/advisories/12317/
http://www.openpkg.org/security/OpenPKG-SA-2004.036-cvstrac.html

Credit

Thanks to Christoph Jeschke for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

Date Public:2004-08-15
Date First Published:2004-08-23
Date Last Updated:2004-08-25
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:2.81
Document Revision:9

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader