Chi Kien Uong Guestbook HTML Injection Vulnerability
BID:8895
Info
Chi Kien Uong Guestbook HTML Injection Vulnerability
| Bugtraq ID: | 8895 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2003 12:00AM |
| Updated: | Oct 27 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Joshua P. Miller <[email protected]>. |
| Vulnerable: |
Chi Kien Uong Guestbook 1.51 |
| Not Vulnerable: | |
Discussion
Chi Kien Uong Guestbook HTML Injection Vulnerability
It has been reported that Chi Kien Uong Guestbook may be prone to an HTML injection vulnerability. The issue has been reported to exist due to insufficient sanitization of user-supplied data during a message post. An attacker may submit a malicious post to inject arbitrary HTML into dynamically generated content.
This vulnerability may be exploited to execute arbitrary HTML and script code in the browser of an unsuspecting user who views the malicious post. Code execution will occur in the context of the vulnerable site. This issue may be exploited to steal cookie based credentials other attacks may also be possible.
It has been reported that Chi Kien Uong Guestbook may be prone to an HTML injection vulnerability. The issue has been reported to exist due to insufficient sanitization of user-supplied data during a message post. An attacker may submit a malicious post to inject arbitrary HTML into dynamically generated content.
This vulnerability may be exploited to execute arbitrary HTML and script code in the browser of an unsuspecting user who views the malicious post. Code execution will occur in the context of the vulnerable site. This issue may be exploited to steal cookie based credentials other attacks may also be possible.
Exploit / POC
Chi Kien Uong Guestbook HTML Injection Vulnerability
No exploit required.
No exploit required.
Solution / Fix
Chi Kien Uong Guestbook HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Chi Kien Uong Guestbook HTML Injection Vulnerability
References:
References:
- New Vulnerability ("Joshua P. Miller"
)