WackoWiki Double Quoted Input HTML...

- AV AC AU C I A
发布: 2003-04-30
修订: 2025-04-13

WackoWiki is reported affected by an HTML injection vulnerability. This issue is due to the affected software not properly sanitizing user-supplied input. Specifically the problem is related to how the application handles input that is enclosed in two instances of double-quote characters (""). An attacker may leverage this issue to execute arbritrary script code in the browser of an unsuspecting user. This would occur in the security context of the site hosting the vulnerable software. This may facilitate the theft of cookie-based authentication credentials, loss of integrity, or other attacks.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息