header-logo
Suggest Exploit
vendor:
Web Wiz Forums
by:
Not mentioned
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Web Wiz Forums
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE: Not assigned
CPE: a:web_wiz:web_wiz_forums
Metasploit:
Other Scripts:
Platforms Tested: Not specified
Unknown

Cross-Site Scripting Vulnerability in Web Wiz Forums

The Web Wiz Forums software is vulnerable to a cross-site scripting attack due to improper sanitization of user-supplied data in the 'registration_rules.asp' script. An attacker can exploit this vulnerability to steal cookie authentication credentials or perform other types of attacks.

Mitigation:

Apply the vendor-supplied patch or upgrade to a newer version of the software.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/10555/info

A vulnerability exists in the Web Wiz Forums software that may allow a remote user to launch cross-site scripting attacks. The problem is reported to exist due to improper sanitizing of user-supplied data passed to the 'registration_rules.asp' script.

An attacker can exploit this issue to steal cookie authentication credentials, or perform other types of attacks.

registration_rules.asp?FID=%22%3E%3Cscript%3Ealert%28%27Vulnerable%2520%21%2
7%29%3C%2Fscript%3E