Filebased Guestbook 'Comment' HTML Injection Vulnerability
BID:7104
Info
Filebased Guestbook 'Comment' HTML Injection Vulnerability
| Bugtraq ID: | 7104 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2003 12:00AM |
| Updated: | Mar 14 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to flur <[email protected]>. |
| Vulnerable: |
Filebased Guestbook Filebased Guestbook 1.1.3 |
| Not Vulnerable: | |
Discussion
Filebased Guestbook 'Comment' HTML Injection Vulnerability
It has been reported that Filebased Guestbook is prone to HTML injection attacks. This problem occurs due to Filebased Guestbook insufficiently sanitizing user-supplied input.
As a result, attackers may embed malicious script code or HTML into forum posts. When a malicious post is viewed by another user, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the software.
It has been reported that Filebased Guestbook is prone to HTML injection attacks. This problem occurs due to Filebased Guestbook insufficiently sanitizing user-supplied input.
As a result, attackers may embed malicious script code or HTML into forum posts. When a malicious post is viewed by another user, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the software.
Exploit / POC
Filebased Guestbook 'Comment' HTML Injection Vulnerability
No exploit is required.
No exploit is required.