vendor:
WebCT Campus Edition
by:
Benjamin "balupton" Lupton
N/A
CVSS
N/A
HTML-injection
79
CWE
Product Name: WebCT Campus Edition
Affected Version From: 4.1.5.8
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
WebCT HTML-injection Vulnerability
WebCT is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Mitigation:
Unknown