FipsGuestbook New_Entry.ASP HTML Injection Vulnerability
BID:7339
Info
FipsGuestbook New_Entry.ASP HTML Injection Vulnerability
| Bugtraq ID: | 7339 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 2003 12:00AM |
| Updated: | Apr 14 2003 12:00AM |
| Credit: | Discovery of this issue is credited to "drG4njubas" <[email protected]>. |
| Vulnerable: |
fipsASP fipsGuestbook 1.12.7 |
| Not Vulnerable: | |
Discussion
FipsGuestbook New_Entry.ASP HTML Injection Vulnerability
fipsGuestbook does not sufficiently sanitize form data of HTML and script code. This could allow a malicious remote user to inject hostile HTML and script code into the guestbook. This code will be displayed and possibly interpreted when the guestbook is viewed by other users.
This issue was reported in fipsGuestbook 1.12.7. Other versions may also be affected.
fipsGuestbook does not sufficiently sanitize form data of HTML and script code. This could allow a malicious remote user to inject hostile HTML and script code into the guestbook. This code will be displayed and possibly interpreted when the guestbook is viewed by other users.
This issue was reported in fipsGuestbook 1.12.7. Other versions may also be affected.
Exploit / POC
FipsGuestbook New_Entry.ASP HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
FipsGuestbook New_Entry.ASP HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
FipsGuestbook New_Entry.ASP HTML Injection Vulnerability
References:
References:
- fipsASP Homepage (fipsASP)
- FipsGuestbook Version 1.12.7 script injection. ("drG4njubas"
)