Phaziz Guestbook Multiple HTML Injection Vulnerabilities
BID:18495
CVE-2006-2994 |Info
Phaziz Guestbook Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 18495 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2994 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2006 12:00AM |
| Updated: | Jul 06 2016 01:33PM |
| Credit: | Luny is credited with discovering this vulnerability. |
| Vulnerable: |
Phaziz.com Phaziz Guestbook 2.0 |
| Not Vulnerable: | |
Discussion
Phaziz Guestbook Multiple HTML Injection Vulnerabilities
Phaziz Guestbook is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
Phaziz Guestbook is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input.
An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.
Exploit / POC
Phaziz Guestbook Multiple HTML Injection Vulnerabilities
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
Phaziz Guestbook Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].