TSguestbook Message Field HTML Injection Vulnerability
BID:8520
Info
TSguestbook Message Field HTML Injection Vulnerability
| Bugtraq ID: | 8520 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2003 12:00AM |
| Updated: | Sep 01 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Trash-80 - [email protected]. |
| Vulnerable: |
TSguestbook TSguestbook 2.1 |
| Not Vulnerable: | |
Discussion
TSguestbook Message Field HTML Injection Vulnerability
It has been reported that TSguestbook may be prone to HTML injection attacks. The problem is said to occur due to insufficient sanitization of user-supplied input within the 'message' field. As a result, an attacker may post a guestbook entry including malicious HTML or script code within the said field. This could result in the execution of arbitrary code within the browser of an unsuspecting guestbook user.
It has been reported that TSguestbook may be prone to HTML injection attacks. The problem is said to occur due to insufficient sanitization of user-supplied input within the 'message' field. As a result, an attacker may post a guestbook entry including malicious HTML or script code within the said field. This could result in the execution of arbitrary code within the browser of an unsuspecting guestbook user.
Exploit / POC
TSguestbook Message Field HTML Injection Vulnerability
No exploit is required. The following proof of concept guestbook entry has been provided to demonstrate exploitation.
Name: Zone-h Security Team
Email: [email protected]
ICQ: 11111111
Homepage: http://www.zone-h.org
Message:<script>alert('Zone-H')</script>
No exploit is required. The following proof of concept guestbook entry has been provided to demonstrate exploitation.
Name: Zone-h Security Team
Email: [email protected]
ICQ: 11111111
Homepage: http://www.zone-h.org
Message:<script>alert('Zone-H')</script>
Solution / Fix
TSguestbook Message Field HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.