SignHere Guestbook HTML Injection Vulnerability
BID:7289
Info
SignHere Guestbook HTML Injection Vulnerability
| Bugtraq ID: | 7289 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 05 2003 12:00AM |
| Updated: | Apr 05 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "drG4njubas" <[email protected]>. |
| Vulnerable: |
Bitstrike Software SignHere Guestbook |
| Not Vulnerable: | |
Discussion
SignHere Guestbook HTML Injection Vulnerability
It has been reported that SignHere does not sufficiently filter user-supplied values from the 'email' field. As a result, attackers may embed malicious script code or HTML into SignHere posts.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
It has been reported that SignHere does not sufficiently filter user-supplied values from the 'email' field. As a result, attackers may embed malicious script code or HTML into SignHere posts.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
Exploit / POC
SignHere Guestbook HTML Injection Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
SignHere Guestbook HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.