Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting

EDB-ID:

22986

CVE:



Platform:

PHP

Date:

2003-08-04


source: https://www.securityfocus.com/bid/8339/info

It is possible to create an authentication or access control page, using Dreamweaver MX PHP Authentication Suite. This script will generate an error page that contains dynamic content when a user fails to authenticate correctly to the site.

A cross-site-scripting vulnerability has been reported to affect PHP authentication functions used in PHP access control pages created with the Macromedia Dreamweaver MX PHP Authentication Suite.

An attacker may exploit this condition to execute arbitrary HTML code in the browser of an unsuspecting user.

http://www.example.com/[PATH]/[LOGIN PAGE].php?[ACCESS DENIED VARIABLE]
="><script>alert('.::\/\|NSRG-18-7|/\/::.');</script>