« EC Watching Microsoft Security Moves | | SecurityDocs: Designing Secure Networks Based on the Software »

Bugtraq: Zoomblog IMG BBCode Tag JavaScript Injection Vulnerability


Bugtraq: Zoomblog IMG BBCode Tag JavaScript Injection Vulnerability
SecurityFocus - Zoomblog is prone to javascript injection attacks. Zoomblog does not adequately filter tags from various fields. It is possible for a malicious Zoomblog user to inject hostile javascript code into the commentary via form fields. :

Technorati tags: