|
|
|
![]() |
Vulnerability Note VU#782243TDForum does not adequately validate user input thereby allowing users to embed malicious script code in messagesOverviewTDForum does not properly filter HTML scripting tags from user input, allowing users to post malicious scripts that may be executed unwittingly by other users.I. DescriptionTDForum is a commercial software package providing dynamic web forum capabilities. Versions 1.2 and earlier of TDForum do not properly filter HTML tags, allowing malicious users to execute client-side scripting on other users' systems.II. ImpactUsers may be tricked into running scripts embedded in forum posts by malicious users.III. SolutionThe CERT/CC is currently unaware of a practical solution to this problem.Systems Affected
ReferencesCA-2000-02 Thanks to Larry Lung for reporting this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||