Advertisement






Invision Power Board D22-Shoutbox HTML Injections

CVE Category Price Severity
CVE-2011-4070 CWE-79 $200 - $2,500 High
Author Risk Exploitation Type Date
Unknown High Remote 2007-08-26
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2007080116

Below is a copy:

[HSC] Invision Power Board D22-Shoutbox HTML Injections

D22-Shoutbox suffers from improper validation of HTMl tags filtration. 
An attacker may leverage this issue to have arbitrary script code execute
in the browser of an unsuspecting user in the context of the affected site.
This may help the attacker steal cookie-based authentication credentials and
launch other attacks. A successful script could allow an attacker to compromise
the application, access or modify data, or exploit vulnerabilities in the
underlying database implementation.

Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz

Class: Input Validation Error

Remote: Yes
Local: N/A

Product: D22-Shoutbox
Version:  N/A
Vendor:  http://www.dscripting.com/

Exploit is not needed, Attackers can exploit these issues via a web client.

Only becoming a hacker you can stop a hacker. Were can you learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum