IdealBB 1.4.9 Beta - HTML Injection

EDB-ID:

23055

CVE:

N/A


Author:

Scott M

Type:

webapps


Platform:

ASP

Date:

2003-08-23


source: https://www.securityfocus.com/bid/8480/info

IdealBB is prone to an HTML injection vulnerability. This could permit remote attackers to inject malicious HTML and script code into board messages. The attacker's code may be rendered in the web browser of the user viewing the malicious message.

<a href="http://www.google.com" onclick="j&#97;vascript:alert(do&#99;ument.cookie);">Google</a>