MLdonkey 2.5-4 - Cross-Site Scripting

EDB-ID:

23320


Platform:

Multiple

Published:

2003-10-31

source: http://www.securityfocus.com/bid/8946/info

It has been reported that the Mldonkey web interface is prone to cross-site scripting attacks when reporting errors. The problem occurs due to insufficient sanitization of script code within requests. This could potentially allow an attacker to carry out a variety of attacks on a user.

http://127.0.0.1:4080/<script>...</script>