E-Guest Guest Book Script Injection Vulnerability
BID:5128
Info
E-Guest Guest Book Script Injection Vulnerability
| Bugtraq ID: | 5128 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2002 12:00AM |
| Updated: | Jun 30 2002 12:00AM |
| Credit: | Vulnerability discovery credited to DownBload <[email protected]>. |
| Vulnerable: |
Leung Eric E-Guest 1.1 |
| Not Vulnerable: | |
Discussion
E-Guest Guest Book Script Injection Vulnerability
E-Guest guest book is a freely available, open source guest book. It is designed for Unix and Linux operating systems.
E-Guest does not properly filter script code from some fields of the guest book entries. It is possible for a remote user to enter HTML and script code in the name, email, homepage, and location fields. Upon visiting the page, this script code would be executed in browser of the visiting user.
E-Guest guest book is a freely available, open source guest book. It is designed for Unix and Linux operating systems.
E-Guest does not properly filter script code from some fields of the guest book entries. It is possible for a remote user to enter HTML and script code in the name, email, homepage, and location fields. Upon visiting the page, this script code would be executed in browser of the visiting user.
Exploit / POC
E-Guest Guest Book Script Injection Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
E-Guest Guest Book Script Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
E-Guest Guest Book Script Injection Vulnerability
References:
References: