<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Support Forum - Topic: Cross-scripting issue with Submit News function?</title>
		<link>http://www.kriesi.at/support/topic/cross-scripting-issue-with-submit-news-function</link>
		<description>Support Forum - Topic: Cross-scripting issue with Submit News function?</description>
		<language>en-US</language>
		<pubDate>Tue, 21 May 2013 04:55:22 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.kriesi.at/support/search.php</link>
		</textInput>
		<atom:link href="http://www.kriesi.at/support/rss/topic/cross-scripting-issue-with-submit-news-function" rel="self" type="application/rss+xml" />

		<item>
			<title>Dude on "Cross-scripting issue with Submit News function?"</title>
			<link>http://www.kriesi.at/support/topic/cross-scripting-issue-with-submit-news-function#post-32951</link>
			<pubDate>Thu, 24 Nov 2011 07:22:40 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">32951@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey,&#60;br /&#62;
I don't think this applies to our template because the user input is converted/treated as text variables only and the server won't execute it. It just sends the text content to your mail client with the php mail() function. Basically the user can enter anything he like but unless the code isn't executed nothing will happen. You just get a wired mail....
&#60;/p&#62;</description>
		</item>
		<item>
			<title>crsbrgs on "Cross-scripting issue with Submit News function?"</title>
			<link>http://www.kriesi.at/support/topic/cross-scripting-issue-with-submit-news-function#post-32889</link>
			<pubDate>Wed, 23 Nov 2011 17:51:32 +0000</pubDate>
			<dc:creator>crsbrgs</dc:creator>
			<guid isPermaLink="false">32889@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi,&#60;/p&#62;
&#60;p&#62;I am using the security scan from websiteprotection.com and they issued a warning &#34;Your Web server is vulnerable to cross-site scripting attacks.&#34;&#60;/p&#62;
&#60;p&#62;Is there a patch for that?&#60;/p&#62;
&#60;p&#62;&#34;Description:&#60;/p&#62;
&#60;p&#62;Your website contains pages that do not properly sanitize visitor-provided input to make sure it contains no malicious content or scripts. Cross-site scripting vulnerabilities let malicious users execute arbitrary HTML or script code in another visitor'&#60;br /&#62;
s browser.&#60;br /&#62;
See Also:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://en.wikipedia.org/wiki/Cross_site_scripting#Non-persistent&#34; rel=&#34;nofollow&#34;&#62;http://en.wikipedia.org/wiki/Cross_site_scripting#Non-persistent&#60;/a&#62; &#60;a href=&#34;http://jeremiahgrossman.blogspot.com/2009/06/results-unicode-leftright-pointing.html&#34; rel=&#34;nofollow&#34;&#62;http://jeremiahgrossman.blogspot.com/2009/06/results-unicode-leftright-pointing.html&#60;/a&#62; &#60;a href=&#34;http://projects.webappsec.org/Cross-Site+Scriptin&#34; rel=&#34;nofollow&#34;&#62;http://projects.webappsec.org/Cross-Site+Scriptin&#60;/a&#62; &#60;a href=&#34;http://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet#Escaping_.28aka_Output_Encoding.29&#34; rel=&#34;nofollow&#34;&#62;http://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet#Escaping_.28aka_Output_Encoding.29&#60;/a&#62;&#60;br /&#62;
Risk Factor:&#60;/p&#62;
&#60;p&#62;Medium / CVSS Base Score : 4.3(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)&#60;br /&#62;
Solution:&#60;/p&#62;
&#60;p&#62;Restrict access to the vulnerable application. Contact the vendor for a patch or upgrade.&#60;/p&#62;
&#60;p&#62;Output:&#60;br /&#62;
Using the POST HTTP method, Site Scanner found that :&#60;br /&#62;
+ The following resources may be vulnerable to cross-site scripting (comprehensive test) :&#60;br /&#62;
+ The 'website' parameter of the /wp-content/themes/newscast/submit_news.php CGI :&#60;br /&#62;
/wp-content/themes/newscast/submit_news.php [website=&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;foobar204&#60;br /&#62;
&#38;gt;&#38;gt;&#38;gt;&#38;gt;&#38;gt;&#38;amp;imageURL=&#38;amp;myblogname=The Technocon News Submission&#38;amp;height=580&#38;amp;widt&#60;br /&#62;
h=420&#38;amp;iframe=true&#38;amp;Subject=&#38;amp;message=&#38;amp;email=&#38;amp;yourname=&#38;amp;Send=Send&#38;amp;myemail=s&#60;br /&#62;
(addressdeleted)@live.com]&#60;br /&#62;
-------- output --------&#60;br /&#62;
&#38;lt;/p&#38;gt;&#60;br /&#62;
&#38;lt;p class=&#34;error&#34; &#38;gt;&#38;lt;label for=&#34;email&#34;&#38;gt;E-Mail*&#38;lt;/label&#38;gt;&#38;lt;input name=&#34;e [...]&#60;br /&#62;
&#38;lt;p&#38;gt;&#38;lt;label for=&#34;website&#34;&#38;gt;Full Story Link*&#38;lt;/label&#38;gt;&#38;lt;input name=&#34;website&#34; cl&#60;br /&#62;
ass=&#34;text_input is_empty&#34; type=&#34;text&#34; id=&#34;website&#34; size=&#34;20&#34; value=&#34;&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#60;br /&#62;
&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;&#38;lt;foobar204&#38;gt;&#38;gt;&#38;gt;&#38;gt;&#38;gt;&#34;/&#38;gt;&#38;lt;/p&#38;gt;&#60;br /&#62;
&#38;lt;p&#38;gt;&#38;lt;label for=&#34;imageURL&#34;&#38;gt;Preview Image URL&#38;lt;/label&#38;gt;&#38;lt;input name=&#34;ima [...]&#60;br /&#62;
------------------------&#60;br /&#62;
Other references : CWE:79, CWE:80, CWE:81, CWE:83, CWE:20, CWE:74, CWE:442, CWE:712, CWE:722, CWE:725, CWE:811, CWE:751, CWE:801, CWE:116, CWE:692, CWE:87, CWE:85, CWE:86, CWE:84
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
