Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

SignHere guestbook vulnerability.
From: "drG4njubas" <drG4nj () mail ru>
Date: Sat, 5 Apr 2003 13:07:05 +0400

This advisory nd other useful files 
can be found at www.blacktigerz.org

Subject:
SignHere guestbook vulnerability.

Description:
Free, easy-to-use guestbook. Main features are: message text 
formatting (bold text, urls etc.); inserting smiles as icons; 
web-based administration; email notifications about new posts. 
Also html output is optimized to maximize download speed. 

Vendor:
Bitstrike software.
http://www.bitstrike.com

Vulnerability:
Default.asp neglects filtering user input allowing 
for script injection to the guestbook via "Email" 
field. The injected script will be executed in 
anyones browser who visits the guestbook.

____________________________
Best Regards,   drG4njubas
Black Tigerz Research Group
http://www.blacktigerz.org


  By Date           By Thread  

Current thread:
  • SignHere guestbook vulnerability. drG4njubas (Apr 05)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]