vendor:
by:
InterN0T
5.5
CVSS
MEDIUM
Cross Site Scripting and HTML Injection
79
CWE
Product Name:
Affected Version From: 1/1/2008
Affected Version To: 1/1/2008
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Internet Explorer 7 (FireFox 3 was tested for the other vulnerabilities)
2008
TBDev – Cross Site Scripting and HTML Injection Vulnerabilities
The TBDev software is vulnerable to Cross Site Scripting and HTML Injection attacks. The 'returnto' parameter is not properly sanitized in several pages, allowing an attacker to inject malicious scripts or redirect users to a different website. The 'Info' field and 'Avatar' field are also vulnerable to HTML Injection attacks. These vulnerabilities can be exploited by sysops, mods, and even end users who need to log in. Internet Explorer 6 and 7 are affected by the HTML Injection vulnerability.
Mitigation:
Secure redirection calls with referer headers and filter bad characters.