OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
ZH2003-14SA (security advisory): aspBoard XSS Vulnerability

From: G00db0y (G00db0yzone-h.org)
Date: Tue Aug 05 2003 - 05:05:00 CDT


ZH2003-14SA (security advisory): aspBoard XSS Vulnerability

Published: 5 august 2003

Released: 5 august 2003

Name: aspBoard

Affected Systems: 1.2

Issue: Remote attackers can inject XSS script

Author: G00db0yzone-h.org

Vendor: http://www.freezingcold.com

Description

***********

Zone-h Security Team has discovered a flaw in
aspBoard 1.2 (and older versions?). aspBoard is a
"Message Board Component for ASP Internet Applications".

Details

*******
 
The posting procedure needs: Your Name, Your Email, Your
URL, a subject and your message. It's possible to inject
XSS script in the url variable.

For example try this:

Your Name: John Doe

Your Email: johndoejohndoe.com

Your URL: <script>alert('Zone-h')</script>

Subject: Hi

Your Message: Zone-h Security Team

Solution:

*********

The vendor has been contacted and a patch is not yet produced

Suggestions:

************

Filter the script

G00db0y - www.zone-h.org admin

Original advisory here: http://www.zone-h.org/en/advisories/read/id=2834/