|
|
| |
| BoastMachine is "a one of its kind Blog/Journal/Article publishing system". The product suffers from a cross-site scripting vulnerability allowing remote attackers to insert malicious HTML and/or JavaScript into the web pages returned by the product. |
| |
Credit:
The information has been provided by David S. Ferreira.
|
| |
Vulnerable systems:
* bMachine version 2.6
This Blog system, based in PHP, suffers from cross-site scripting vulnerability (CSS/XSS). This can be exploited by including arbitrary HTML or script code in the comment form, using field's name, and even the comment box. This will execute any of the malicious code when viewing the comments on that message.
|
|
|
|
|
|
|
|