Big Blue Guestbook HTML Injection Vulnerabilities

看板Bugtraq作者時間19年前 (2007/04/24 05:17), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Hi friends, Big Blue Guestbook software is prone to HTML injection attacks. This issue is exposed via the message form field in the guestbook entry submission form. Exploitation could permit remote attackers to persistently inject hostile HTML and script code into guestbook content. This could allow for theft of cookie-based authentications or other attacks, such as those which misrepresent guestbook content. vendor : http://www.ben-barnett.com/guestbook.php download : http://www.ben-barnett.com/BigBlueGuestbook.zip Thnx: www.starhack.org // CaRaMeL
文章代碼(AID): #16BI9C00 (Bugtraq)