Ben's Guestbook HTML Injection Vulnerability
BID:9183
Info
Ben's Guestbook HTML Injection Vulnerability
| Bugtraq ID: | 9183 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2003 12:00AM |
| Updated: | Dec 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to David S. Ferreira. |
| Vulnerable: |
Bens Scripts Guestbook 1.0 |
| Not Vulnerable: | |
Discussion
Ben's Guestbook HTML Injection Vulnerability
A vulnerability has been reported in the software that may allow a remote attacker to execute HTML and script code in a user's browser. The issue is reported to be present in the comments field of the application. The problem exists due to insufficient sanitization of user-supplied input. It may be possible for an attacker to include malicious HTML code in one of the vulnerable fields. The injected code could then be interpreted by the browser of a user visiting the vulnerable site.
A vulnerability has been reported in the software that may allow a remote attacker to execute HTML and script code in a user's browser. The issue is reported to be present in the comments field of the application. The problem exists due to insufficient sanitization of user-supplied input. It may be possible for an attacker to include malicious HTML code in one of the vulnerable fields. The injected code could then be interpreted by the browser of a user visiting the vulnerable site.
Exploit / POC
Ben's Guestbook HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Ben's Guestbook HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.