MyGuestbook Form.php HTML Injection Vulnerability
BID:6906
Info
MyGuestbook Form.php HTML Injection Vulnerability
| Bugtraq ID: | 6906 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2003 12:00AM |
| Updated: | Feb 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
tefonline.net Myguestbook 3.0 |
| Not Vulnerable: | |
Discussion
MyGuestbook Form.php HTML Injection Vulnerability
MyGuestbook does not adequately filter HTML tags from various fields. This may enable an attacker to inject arbitrary HMTL code into pages that are generated by the guestbook.
The attacker's code may be executed in the web client of users who view the pages generated by the guestbook, in the security context of the website hosting the software.
Attackers may potentially exploit this issue to hijack web content or to steal cookie-based authentication credentials.
This vulnerability has been reported for MyGuestbook version 3.0, previous versions may also be affected.
MyGuestbook does not adequately filter HTML tags from various fields. This may enable an attacker to inject arbitrary HMTL code into pages that are generated by the guestbook.
The attacker's code may be executed in the web client of users who view the pages generated by the guestbook, in the security context of the website hosting the software.
Attackers may potentially exploit this issue to hijack web content or to steal cookie-based authentication credentials.
This vulnerability has been reported for MyGuestbook version 3.0, previous versions may also be affected.
Exploit / POC
MyGuestbook Form.php HTML Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.