Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wp-pagenavi domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u918112125/domains/exploit.company/public_html/wp-includes/functions.php on line 6114
MySpace Scripts Poll Creator HTML Injection Vulnerability - exploit.company
header-logo
Suggest Exploit
vendor:
Poll Creator
by:
Unknown
7.5
CVSS
HIGH
HTML Injection
79
CWE
Product Name: Poll Creator
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:myspace_scripts:poll_creator
Metasploit:
Other Scripts:
Platforms Tested: Unknown
Unknown

MySpace Scripts Poll Creator HTML Injection Vulnerability

The MySpace Scripts Poll Creator application is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. This allows an attacker to inject malicious HTML or JavaScript code that can run in the context of the affected site. This can potentially lead to the theft of cookie-based authentication credentials and allow the attacker to control how the site is rendered to the user. Other attacks are also possible.

Mitigation:

To mitigate this vulnerability, it is recommended to properly sanitize user input before using it in dynamically generated content. This can be done by implementing input validation and output encoding techniques.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/26544/info

MySpace Scripts Poll Creator is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. 

http://www.example.com/poll/index.php?action=create_new