Dynamic Guestbook Cross-Agent Scripting Vulnerability
BID:4422
Info
Dynamic Guestbook Cross-Agent Scripting Vulnerability
| Bugtraq ID: | 4422 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0551 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to "Florian Hobelsberger / BlueScreen" <[email protected]>. |
| Vulnerable: |
Dynamic Guestbook Dynamic Guestbook 3.0 |
| Not Vulnerable: | |
Discussion
Dynamic Guestbook Cross-Agent Scripting Vulnerability
Dynamic Guestbook does not sufficiently sanitize potentially malicious characters, such as HTML tags, from form fields. As a result, it may be possible to inject arbitrary script code into pages that are generated by the guestbook. The script will execute in the clients of other users when the malicious guestbook entries are viewed.
Dynamic Guestbook does not sufficiently sanitize potentially malicious characters, such as HTML tags, from form fields. As a result, it may be possible to inject arbitrary script code into pages that are generated by the guestbook. The script will execute in the clients of other users when the malicious guestbook entries are viewed.
Exploit / POC
Dynamic Guestbook Cross-Agent Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Dynamic Guestbook Cross-Agent Scripting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.