1
tuxsoul
Xoops Pool Module IMG Tag HTML Injection Vulnerability
  • 2006/1/10 3:10

  • tuxsoul

  • Just popping in

  • Posts: 13

  • Since: 2006/1/10


Xoops Pool Module IMG Tag HTML Injection Vulnerability

The XOOPS Pool Module is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

http://www.securityfocus.com/bid/16189/info

-------

I see this report in securityfocus.com, somebody know about this ?

sorry my english is bad

2
m0nty
Re: Xoops Pool Module IMG Tag HTML Injection Vulnerability
  • 2006/1/10 3:25

  • m0nty

  • XOOPS is my life!

  • Posts: 3337

  • Since: 2003/10/24


never heard of Pool Module myself..

3
tuxsoul
Re: Xoops Pool Module IMG Tag HTML Injection Vulnerability
  • 2006/1/10 3:37

  • tuxsoul

  • Just popping in

  • Posts: 13

  • Since: 2006/1/10


Quote:

m0nty wrote:
never heard of Pool Module myself..


I'm new using xoops, searching for this module, don't exist, but maybe to refer a poll module ???

sorry my english is bad

Login

Who's Online

55 user(s) are online (42 user(s) are browsing Support Forums)


Members: 0


Guests: 55


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Aug 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits