Ocean12 ASP Guestbook Manager Code Injection Vulnerability
BID:7329
Info
Ocean12 ASP Guestbook Manager Code Injection Vulnerability
| Bugtraq ID: | 7329 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2003 12:00AM |
| Updated: | Apr 11 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "drG4njubas" <[email protected]>. |
| Vulnerable: |
Ocean12 Technologies ASP Guestbook Manager 1.0 |
| Not Vulnerable: | |
Discussion
Ocean12 ASP Guestbook Manager Code Injection Vulnerability
Ocean12 ASP Guestbook Manager has been reported prone to a HTML Code injection vulnerability.
Due to a lack of sanitization performed on several guestbook form fields, an attacker may inject arbitrary HTML code into dynamically generated Guestbook Manager pages.
The injected script code will execute in the security context of the Guestbook Manager site, potentially allowing an attacker to hijack web content or to steal cookie-based authentication credentials. It may also be possible to take arbitrary actions as the victim user, including posting or deleting content.
Ocean12 ASP Guestbook Manager has been reported prone to a HTML Code injection vulnerability.
Due to a lack of sanitization performed on several guestbook form fields, an attacker may inject arbitrary HTML code into dynamically generated Guestbook Manager pages.
The injected script code will execute in the security context of the Guestbook Manager site, potentially allowing an attacker to hijack web content or to steal cookie-based authentication credentials. It may also be possible to take arbitrary actions as the victim user, including posting or deleting content.
Exploit / POC
Ocean12 ASP Guestbook Manager Code Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Ocean12 ASP Guestbook Manager Code Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ocean12 ASP Guestbook Manager Code Injection Vulnerability
References:
References:
- ASP Guestbook Manager Homepage (Ocean12)
- Ocean12 ASP Guestbook Manager v1.00 ("drG4njubas"
)