ASPJar Guestbook HTML Injection Vulnerability
BID:4671
Info
ASPJar Guestbook HTML Injection Vulnerability
| Bugtraq ID: | 4671 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2002 12:00AM |
| Updated: | May 04 2002 12:00AM |
| Credit: | Posted to BugTraq on May 5, 2002 by frog frog <[email protected]> |
| Vulnerable: |
ASPJar Guestbook 1.0 |
| Not Vulnerable: | |
Discussion
ASPJar Guestbook HTML Injection Vulnerability
ASPJar Advanced ASP Guestbook is prone to HTML injection attacks. It is possible for a malicious guestbook user to inject hostile HTML and script code into the guestbook via form fields. This code may be rendered in the browser of a web user who views the guestbook.
In addition to this, an unauthenticated "delete" script allows removal of other guestbook entries.
ASPJar Advanced ASP Guestbook is prone to HTML injection attacks. It is possible for a malicious guestbook user to inject hostile HTML and script code into the guestbook via form fields. This code may be rendered in the browser of a web user who views the guestbook.
In addition to this, an unauthenticated "delete" script allows removal of other guestbook entries.
Exploit / POC
ASPJar Guestbook HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.