Overview
WebBoard does not adequately validate user input, allowing attackers to execute arbitrary JavaScript code on other WebBoard users' systems.
Description
WebBoard is a web application which includes a real-time chat server, using JavaScript alerts to display messages received by other users. WebBoard does not adequately filter messages sent through the chat server, allowing attackers to execute arbitrary JavaScript code on other users' systems. |
Impact
Attackers can execute arbitrary JavaScript code on other WebBoard client users' systems. |
Solution
Upgrade Upgrade to WebBoard version 4.2, available at: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Helmuth Antholzer for reporting this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
CVE IDs: | CVE-2001-0743 |
Severity Metric: | 2.57 |
Date Public: | 2001-06-02 |
Date First Published: | 2002-09-27 |
Date Last Updated: | 2003-09-23 02:34 UTC |
Document Revision: | 3 |