vendor:
BBG/RPG browser game
by:
M.Jock3R
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: BBG/RPG browser game
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Sp2 FR
2009
Dominant Creature BBG/RPG browser game XSS vulnerabilities
Dominant Creature BBG/RPG browser game is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can exploit this vulnerability by sending a malicious script in the message box of the Duel opponents page. The malicious script will be executed when the victim views the message. This can be used to steal the victim's cookies and gain access to their account.
Mitigation:
Input validation should be used to prevent malicious scripts from being executed. The application should also use a Content Security Policy (CSP) to prevent malicious scripts from being executed.