MLdonkey 2.5-4 - Cross-Site Scripting

Related Vulnerabilities: CVE-2003-1164  
Publish Date: 31 Oct 2003
Author: Chris Sharp
                							

                source: http://www.securityfocus.com/bid/8946/info

It has been reported that the Mldonkey web interface is prone to cross-site scripting attacks when reporting errors. The problem occurs due to insufficient sanitization of script code within requests. This could potentially allow an attacker to carry out a variety of attacks on a user.

http://127.0.0.1:4080/<script>...</script>