Multiple GuestBookHost HTML Injection Vulnerabilities
BID:8025
Info
Multiple GuestBookHost HTML Injection Vulnerabilities
| Bugtraq ID: | 8025 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2003 12:00AM |
| Updated: | Jun 24 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Julien L." <[email protected]>. |
| Vulnerable: |
GuestBookHost GuestBookHost |
| Not Vulnerable: | |
Discussion
Multiple GuestBookHost HTML Injection Vulnerabilities
Multiple HTML injection vulnerabilities have been reported for GuestBookHost guest books. The problem has been reported to due to a lack of sufficient sanitization performed on user-supplied data. An attacker may inject arbitrary HTML code into GuestBookHost guest book entries.
When the malicious entry is later viewed by a legitimate, the embedded HTML code will be interpreted in their browser.
Multiple HTML injection vulnerabilities have been reported for GuestBookHost guest books. The problem has been reported to due to a lack of sufficient sanitization performed on user-supplied data. An attacker may inject arbitrary HTML code into GuestBookHost guest book entries.
When the malicious entry is later viewed by a legitimate, the embedded HTML code will be interpreted in their browser.
Exploit / POC
Multiple GuestBookHost HTML Injection Vulnerabilities
There is no exploit required.
There is no exploit required.