Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Yet Another Forum.net XSS vulnerabilities

Yet Another Forum.net XSS vulnerabilities

From: maty siman <maty_at_checkmarx.com>
Date: 2 Apr 2005 17:47:00 -0000
('binary' encoding is not supported, stored as-is) OVERVIEW
=========

"Yet Another Forum.net (http://www.yetanotherforum.net/)
is a opensource discussion forum or bulletin board system
for web sites running ASP.NET. It is ASP.NET based with a
MS SQL backend database.
The full C# source code is available licensed as GPL. "

Several Cross Site Scripting (XSS) vulnerabilities were found.

DETAILS
=======

Due to insufficient input filtering, any user can
insert malicious script code into "name" and "location" fields
and into the "Subject" field of PM.
The scripts may (for example) steal authentication cookies of users
reading messages written by the malicious user.

VULNERABLE VERSIONS
===================

Yet Another Forum.net Version 0.9.9 is vulnerable to this issue.
Prior version were not tested

SOLUTION
========

Yet Another Forum.net's administrator was informed on March 17, 2005.

CREDITS
=======

The vulnerability was researched by Maty Siman (maty_at_checkmarx.com)

--
Maty Siman, CISSP
Web: http://www.checkmarx.com/
Received on Apr 02 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos