search menu icon-carat-right cmu-wordmark

CERT Coordination Center

WebBoard does not adequately validate user input thereby permitting arbitrary JavaScript execution

Vulnerability Note VU#255915

Original Release Date: 2002-09-27 | Last Revised: 2003-09-23

Overview

WebBoard does not adequately validate user input, allowing attackers to execute arbitrary JavaScript code on other WebBoard users' systems.

Description

WebBoard is a web application which includes a real-time chat server, using JavaScript alerts to display messages received by other users. WebBoard does not adequately filter messages sent through the chat server, allowing attackers to execute arbitrary JavaScript code on other users' systems.

Impact

Attackers can execute arbitrary JavaScript code on other WebBoard client users' systems.

Solution

Upgrade

Upgrade to WebBoard version 4.2, available at:

ftp://ftp.chatspace.com/wb/support/software/webboard/webboard_4/windows_edition_msdesql/webboard42.zip

Vendor Information

255915
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Helmuth Antholzer for reporting this vulnerability.

This document was written by Shawn Van Ittersum.

Other Information

CVE IDs: CVE-2001-0743
Severity Metric: 2.57
Date Public: 2001-06-02
Date First Published: 2002-09-27
Date Last Updated: 2003-09-23 02:34 UTC
Document Revision: 3

Sponsored by CISA.