1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Yazd Forum Software Cross-Site Scripting Vulnerabilities

Report ID: SA30760
Source: Secunia
Date of Discovery: 27.06.2008
Criticality: Low
Affects:
Yazd Discussion Forum Software 3.x

Compromise From: From remote
Compromise Type: Cross site scripting

Summary

Some vulnerabilities in Yazd Forum Software, which can be exploited by malicious people to conduct cross-site scripting attacks.

Detailed Description

Some vulnerabilities in Yazd Forum Software, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed to the "q" parameter in search.jsp and to the "msg" parameter in error.jsp and userAccount.jsp is not properly sanitised before being returned to a user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Solution

Edit the source code to ensure that input is properly sanitised.