vendor:
Web Wiz Forums
by:
Not mentioned
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Web Wiz Forums
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE: Not assigned
CPE: a:web_wiz:web_wiz_forums
Platforms Tested: Not specified
Unknown
Cross-Site Scripting Vulnerability in Web Wiz Forums
The Web Wiz Forums software is vulnerable to a cross-site scripting attack due to improper sanitization of user-supplied data in the 'registration_rules.asp' script. An attacker can exploit this vulnerability to steal cookie authentication credentials or perform other types of attacks.
Mitigation:
Apply the vendor-supplied patch or upgrade to a newer version of the software.