AN Guestbook 'country' Parameter HTML Injection Vulnerability
BID:33292
Info
AN Guestbook 'country' Parameter HTML Injection Vulnerability
| Bugtraq ID: | 33292 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2009 12:00AM |
| Updated: | Jan 17 2009 12:32AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
AN Guestbook AN Guestbook 0.7.6 AN Guestbook AN Guestbook 0.7.5 AN Guestbook AN Guestbook 0.7 AN Guestbook AN Guestbook 0.4 |
| Not Vulnerable: |
AN Guestbook AN Guestbook 0.7.7 |
Discussion
AN Guestbook 'country' Parameter HTML Injection Vulnerability
AN Guestbook is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to AN Guestbook 0.7.7 are vulnerable.
AN Guestbook is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to AN Guestbook 0.7.7 are vulnerable.
Exploit / POC
AN Guestbook 'country' Parameter HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
AN Guestbook 'country' Parameter HTML Injection Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
AN Guestbook AN Guestbook 0.4
AN Guestbook AN Guestbook 0.7
AN Guestbook AN Guestbook 0.7.5
AN Guestbook AN Guestbook 0.7.6
Solution:
The vendor has released fixes. Please see the references for more information.
AN Guestbook AN Guestbook 0.4
-
AN Guestbook ang_0_7_7.zip
http://downloads.sourceforge.net/aguestbook/ang_0_7_7.zip?modtime=1231 949070&big_mirror=0
AN Guestbook AN Guestbook 0.7
-
AN Guestbook ang_0_7_7.zip
http://downloads.sourceforge.net/aguestbook/ang_0_7_7.zip?modtime=1231 949070&big_mirror=0
AN Guestbook AN Guestbook 0.7.5
-
AN Guestbook ang_0_7_7.zip
http://downloads.sourceforge.net/aguestbook/ang_0_7_7.zip?modtime=1231 949070&big_mirror=0
AN Guestbook AN Guestbook 0.7.6
-
AN Guestbook ang_0_7_7.zip
http://downloads.sourceforge.net/aguestbook/ang_0_7_7.zip?modtime=1231 949070&big_mirror=0
References
AN Guestbook 'country' Parameter HTML Injection Vulnerability
References:
References:
- AN Guestbook 0.7.7 Release Notes (AN Guestbook)
- AN Guestbook Homepage (AN Guestbook)