Network Security News – Sunday, March 26, 2006 Events
Toast Forums toast.asp Multiple Variable XSS
Toast Forums contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'author', 'subject', 'message' or 'dayprune' variables upon submission to the toast.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more at osvdb.org/24119
Leave a Reply