MyGuestbook Script Injection Vulnerability
BID:4651
Info
MyGuestbook Script Injection Vulnerability
| Bugtraq ID: | 4651 |
| Class: | Unknown |
| CVE: |
CVE-2002-0732 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovery of this issue is credited to "BrainRawt ." <[email protected]>. |
| Vulnerable: |
LEVCGI.COM MyGuestbook 1.0 |
| Not Vulnerable: | |
Discussion
MyGuestbook Script Injection Vulnerability
MyGuestbook is freely available guestbook software. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
MyGuestbook does not adequately filter script code from various fields. This may enable an attacker to inject script code which will be executed in the web client of an arbitrary user who views the guestbook.
Attackers may potentially exploit this issue to hijack web content or to steal cookie-based authentication credentials.
MyGuestbook is freely available guestbook software. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
MyGuestbook does not adequately filter script code from various fields. This may enable an attacker to inject script code which will be executed in the web client of an arbitrary user who views the guestbook.
Attackers may potentially exploit this issue to hijack web content or to steal cookie-based authentication credentials.
Exploit / POC
MyGuestbook Script Injection Vulnerability
The following examples were submitted:
Sign up and post using the "name"
<script>alert('evil+java+script+here')</script>
or
When posting comments just insert the
<script>alert('evil+java+script+here')</script>
to the comments field.
The following examples were submitted:
Sign up and post using the "name"
<script>alert('evil+java+script+here')</script>
or
When posting comments just insert the
<script>alert('evil+java+script+here')</script>
to the comments field.
Solution / Fix
MyGuestbook Script Injection Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.