N.T. index.php username Variable XSS
Posted on 05 April 2006

Vulnerability Description

N.T. contains a flaw that allows a remote cross site scripting attack.
This flaw exists because the application does not validate the 'username'
variable upon submission to the index.php script. This could allow a
user to create a specially crafted URL that would execute arbitrary code
in an administrator's browser when the "Login Log" page is viewed, leading
to a loss of integrity.

Solution Description

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products:

  • Chucky A. Ivey N.T. 1.1.0 Affected

Vulnerability classification:

  • Remote vulnerability
  • Input manipulation attack
  • Impact on integrity
  • Exploit available

External references:

  • Secunia Advisory ID: 19526
  • Other Advisory URL: go there
  • Vendor URL: go there
  • Related OSVDB ID: 24398
  • Mail List Post: go there
  • CVE ID: 2006-1657
  • FrSIRT Advisory: ADV-2006-1243

[ Vulnerabilities main page ]




The HNS Vulnerabilities section is powered by OSVDB



Spotlight

IT security jobs: What's in demand and how to meet it

Posted on 15 May 2013.  |  Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Fri, May 17th
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //