XGB Guestbook User-Embedded Scripting Vulnerability
BID:4513
Info
XGB Guestbook User-Embedded Scripting Vulnerability
| Bugtraq ID: | 4513 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2002 12:00AM |
| Updated: | Apr 15 2002 12:00AM |
| Credit: | Discovered by Markus "Firehack" Köberle <[email protected]> and Florian "BlueScreen" Hobelsberger <[email protected]> from www.IT-Checkpoint.net. |
| Vulnerable: |
x-dev xGB 1.2 |
| Not Vulnerable: | |
Discussion
XGB Guestbook User-Embedded Scripting Vulnerability
xGB is guestbook software. It is written in PHP and will run on most Unix and Linux variants as well as Microsoft Windows operating systems.
xGB allows users to post images in guestbook entries by using special syntax to denote a link to an image. However, script code is not filtered from the image tags ([img][/img]) used by the guestbook. An attacker may cause script code to be executed by arbitrary web users who view the guestbook entries.
xGB is guestbook software. It is written in PHP and will run on most Unix and Linux variants as well as Microsoft Windows operating systems.
xGB allows users to post images in guestbook entries by using special syntax to denote a link to an image. However, script code is not filtered from the image tags ([img][/img]) used by the guestbook. An attacker may cause script code to be executed by arbitrary web users who view the guestbook entries.
Solution / Fix
XGB Guestbook User-Embedded Scripting Vulnerability
Solution:
The vendor has announced that a fix is available. Administrators should contact the vendor about obtaining a fix.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has announced that a fix is available. Administrators should contact the vendor about obtaining a fix.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.