tuxsoul tuxsoul
  • Just popping in
  • Just popping in
  • Joined: 2006/1/9 21:58
  • From Morelos
  • Group: Registered Users
  • Posts: 13
  • Posted on: 2006/1/9 22:10
Xoops Pool Module IMG Tag HTML Injection Vulnerability #1
Xoops Pool Module IMG Tag HTML Injection Vulnerability

The XOOPS Pool Module is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

http://www.securityfocus.com/bid/16189/info

-------

I see this report in securityfocus.com, somebody know about this ?

sorry my english is bad
m0nty m0nty
  • XOOPS is my life!
  • XOOPS is my life!
  • Joined: 2003/10/24 19:30
  • From Derbyshire/UK
  • Group: BANNED Users
  • Posts: 3337
  • Posted on: 2006/1/9 22:25
Re: Xoops Pool Module IMG Tag HTML Injection Vulnerability #2
never heard of Pool Module myself..
tuxsoul tuxsoul
  • Just popping in
  • Just popping in
  • Joined: 2006/1/9 21:58
  • From Morelos
  • Group: Registered Users
  • Posts: 13
  • Posted on: 2006/1/9 22:37
Re: Xoops Pool Module IMG Tag HTML Injection Vulnerability #3
Quote:

m0nty wrote:
never heard of Pool Module myself..


I'm new using xoops, searching for this module, don't exist, but maybe to refer a poll module ???

sorry my english is bad
How to effectively post a question in the Xoops forums? - Read here...
Design by: XOOPS UI/UX Team