OSVDB ID: 3272

Title: Geeklog FAQ Manager Plugin index.php XSS

Info

Disclosure

Sep 30, 2003

Discovery

Unknown

Dates

Exploit

Sep 30, 2003

Solution

Unknown

Description

Geeklog FAQ Manager Plugin contains a flaw that allows a remote Cross Site Scripting attack. This flaw exists because the application does not validate the "t" parameter upon submission to the index.php script. This could allow a user to send a specially crafted request that would execute arbitrary code on the server leading to a loss of integrity. Note: This plugin is not installed by default during a Geeklog installation.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Public
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

PortalParts.com

Geeklog FAQ Manager Plugin

Unknown or Unspecified

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/3272