Skull-Splitter Guestbook Unspecified HTML Injection Vulnerability
BID:12580
Info
Skull-Splitter Guestbook Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 12580 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2005 12:00AM |
| Updated: | Feb 17 2005 12:00AM |
| Credit: | Discovery is credited to Christoph Burchert <[email protected]>. |
| Vulnerable: |
Skull-Splitter Guestbook 2.1 |
| Not Vulnerable: | |
Discussion
Skull-Splitter Guestbook Unspecified HTML Injection Vulnerability
Skull-Splitter Guestbook is reportedly affected by an unspecified HTML injection vulnerability. A victim user who views the vulnerable sections of the site would have the attacker-supplied HTML and script code execute in the security context of the affected site.
Skull-Splitter Guestbook version 2.1 is reported vulnerable, however, other versions may be affected as well.
Skull-Splitter Guestbook is reportedly affected by an unspecified HTML injection vulnerability. A victim user who views the vulnerable sections of the site would have the attacker-supplied HTML and script code execute in the security context of the affected site.
Skull-Splitter Guestbook version 2.1 is reported vulnerable, however, other versions may be affected as well.
Exploit / POC
Skull-Splitter Guestbook Unspecified HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Skull-Splitter Guestbook Unspecified HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Skull-Splitter Guestbook Unspecified HTML Injection Vulnerability
References:
References: