OpenFAQ - HTML injection and XSS (Cross Site Scripting)
SecurityAlert : 850 CVE : CVE-2006-2252 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : Kamil Sienicki (K3 spelunca int pl) Published : 09.05.2006
Affected Software :
OpenFAQ
Advisory Content :
Script: OpenFAQ
Version: 0.4.0 previous version probably too.
Language: PHP
Problem: HTML injection and XSS (Cross Site Scripting)
Vendor: http://sourceforge.net/projects/openfaq
Discovered by: Kamil 'K3' Sienicki
Description:
OpenFAQ is a PHP application that lets Webmasters
administrate a Frequently Asked Questions section on their Web site.
It has an admin section for easily adding questions and answers and
editing the general configuration.
Problem:
A remote user can send via form a specially crafted data.
When admin try to validate questions in administration panel,
specially crafted data will be executed.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.