GuppY Cross-Site Scripting Vulnerability
BID:8768
Info
GuppY Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8768 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2003 12:00AM |
| Updated: | Oct 05 2003 12:00AM |
| Credit: | Discovery is credited to Frog Man <[email protected]>. |
| Vulnerable: |
Guppy GuppY 2.4 p3 |
| Not Vulnerable: |
Guppy GuppY 2.4 p4 |
Discussion
GuppY Cross-Site Scripting Vulnerability
GuppY is reported to be prone to a cross-site scripting vulnerability due to insufficient sanitization of user-supplied input. The problem exists in the postguest module of the software. This issue may allow a remote attacker to execute HTML or script code in user's browser.
Successful exploitation of this vulnerability may allow an attacker to steal cookie-based authentication credentials. Other attacks may also be possible.
GuppY is reported to be prone to a cross-site scripting vulnerability due to insufficient sanitization of user-supplied input. The problem exists in the postguest module of the software. This issue may allow a remote attacker to execute HTML or script code in user's browser.
Successful exploitation of this vulnerability may allow an attacker to steal cookie-based authentication credentials. Other attacks may also be possible.
Solution / Fix
GuppY Cross-Site Scripting Vulnerability
Solution:
The vendor has released a patch and an updated version of GuppY.
Patch: http://www.freeguppy.org/file/guppy_patch.zip
Version 2.4p4: http://www.freeguppy.org/file/guppy.zip
Solution:
The vendor has released a patch and an updated version of GuppY.
Patch: http://www.freeguppy.org/file/guppy_patch.zip
Version 2.4p4: http://www.freeguppy.org/file/guppy.zip
References
GuppY Cross-Site Scripting Vulnerability
References:
References:
- GuppY Cross-site Scripting (GuppY)
- GuppY Homepage (GuppY)
- GuppY : XSS, Files Reading/Writing ("Frog Man"
)