Bugtraq mailing list archives

vuln


From: "ShelzZ" <shelzz () mail ru>
Date: Mon, 29 Mar 2004 01:11:55 +0400

#############################
#0x29a team security advisory
#############################
#Product: Fresh Guest book
#Script: guest.cgi
#Company: WebFresh
#Vulnerability: XSS
#############################
#Overview:
HiGuest is a simple perl-guestbook, which include all standart
guestbook functions.
#Bug: Any remote user can execute html code on the vulnerable system.
The script don't filter incoming data in "Name" area.
#w0w
http://0x29a.hncrew.org


Current thread: