Multiple script injection and cross-site scripting vulnerabilities reportedly affect ZeroBoard. These issues are due to a failure of the application to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary server-side scripts and carry out cross-site scripting attacks against unsuspecting users. This may facilitate a compromise of the host computer, as well as theft of cookie-based authentication credentials. Other attacks are also possible.
Multiple script injection and cross-site scripting vulnerabilities reportedly affect ZeroBoard. These issues are due to a failure of the application to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary server-side scripts and carry out cross-site scripting attacks against unsuspecting users. This may facilitate a compromise of the host computer, as well as theft of cookie-based authentication credentials. Other attacks are also possible.