MyPHP Guestbook Multiple Cross Site Scripting Vulnerabilities
BID:18582
CVE-2006-3063 |Info
MyPHP Guestbook Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 18582 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3063 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2006 12:00AM |
| Updated: | Jun 22 2006 07:50PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
myPHP Guestbook myPHP Guestbook 2.0 myPHP Guestbook myPHP Guestbook 2.0.1 |
| Not Vulnerable: |
myPHP Guestbook myPHP Guestbook 2.0.2 |
Discussion
MyPHP Guestbook Multiple Cross Site Scripting Vulnerabilities
myPHP Guestbook is a web-based guestbook application developed in PHP. It is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
myPHP Guestbook is a web-based guestbook application developed in PHP. It is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
MyPHP Guestbook Multiple Cross Site Scripting Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
MyPHP Guestbook Multiple Cross Site Scripting Vulnerabilities
Solution:
A vendor-supplied patch for these issues is available. Administrators should upgrade to version 2.0.2 or greater.
Solution:
A vendor-supplied patch for these issues is available. Administrators should upgrade to version 2.0.2 or greater.
References
MyPHP Guestbook Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Original Advisory (myPHP Guestbook)
- Stud.IP Home Page (Stud.IP)