Zap Book Script Injection Vulnerability
BID:5131
Info
Zap Book Script Injection Vulnerability
| Bugtraq ID: | 5131 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2002 12:00AM |
| Updated: | Jun 30 2002 12:00AM |
| Credit: | Vulnerability discovery credited to DownBload <[email protected]>. |
| Vulnerable: |
Zap Book Zap Book 1.0.3 |
| Not Vulnerable: | |
Discussion
Zap Book Script Injection Vulnerability
Zap Book is a freely available, open source guest book. It is designed for Unix and Linux operating systems.
Zap Book does not properly filter script code from some fields of the guest book entries. It is possible for a remote user to enter HTML and script code in the name, email, homepage, and location fields. Upon visiting the page, this script code would be executed in browser of the visiting user.
Zap Book is a freely available, open source guest book. It is designed for Unix and Linux operating systems.
Zap Book does not properly filter script code from some fields of the guest book entries. It is possible for a remote user to enter HTML and script code in the name, email, homepage, and location fields. Upon visiting the page, this script code would be executed in browser of the visiting user.
Exploit / POC
Zap Book Script Injection Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Zap Book Script Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Zap Book Script Injection Vulnerability
References:
References: