Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Vulnerable to script injection?
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Forum LockedVulnerable to script injection?

 Post Reply Post Reply
Author
astralis View Drop Down
Newbie
Newbie


Joined: 17 March 2002
Location: United States
Status: Offline
Points: 33
Post Options Post Options   Thanks (0) Thanks(0)   Quote astralis Quote  Post ReplyReply Direct Link To This Post Topic: Vulnerable to script injection?
    Posted: 03 February 2007 at 9:48pm
Is this RTE vulnerable to the following hack?

Malformed ASCII Characters
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 05 February 2007 at 8:58am
This question is only viable if the RTE processed your data, which it doesn't as we do not know how the end user wants to process the data they take from their web forms.

The RTE is like a blank canvas you simply apply it to your sites own existing web forms.

How you process and filter the data from your sites web forms once it is submitted is completely up to you, the RTE doesn't handle this side of things as what you do with the data from your forms could be anything, as you may want the data for emails, databases, etc.

As you apply the RTE to an already existing form on your site then you should already have measures in place that filter this type of thing.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 05 February 2007 at 9:13am
Looking more into the XSS you mention encase we need to strengthen up our own web form processing it looks like this hack will only work on Tom Cat web servers.

As the Web Wiz RTE will not run on Tom Cat this shouldn't be an issue.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.