vendor:
DaCode
by:
SecurityFocus
7.5
CVSS
HIGH
DaCode HTML Injection
79
CWE
Product Name: DaCode
Affected Version From: DaCode 1.0
Affected Version To: DaCode 1.0
Patch Exists: YES
Related CWE: CVE-2002-1490
CPE: o:dacode:dacode_1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2002
Problems with DaCode
DaCode is vulnerable to HTML injection attacks due to insufficient filtering of potentially malicious HTML code from news posts. When a user views a news posting that contains malicious HTML code, the code contained in the posted message would be executed in the browser of the vulnerable user.
Mitigation:
DaCode should filter potentially malicious HTML code from news posts.