about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Advanced Guestbook Multiple Cross-Site Scripting Vulnerabilities


Title Advanced Guestbook Multiple Cross-Site Scripting Vulnerabilities
Published 2005-12-19-12:00AM
Updated 2005-12-19-07:16PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Handrix <handrix_at_morx_org> is credited with the discovery of this vulnerability.
Vulnerable  Advanced Guestbook Advanced Guestbook 2.3.1
Advanced Guestbook Advanced Guestbook 2.2
Not Vulnerable  
Code   No exploit is required.

Example URI have been provided:


http://www.example.com/guestbook/index.php?entry=<script>alert(document.cookie);</script>
http://www.example.com/guestbook/index.php?entry=<iframesrc=http://www.example.com/>

http://www.example.com/guestbook/comment.php?gb_id=1<script>alert(document.cookie);</script>
http://www.example.com/guestbook/comment.php?gb_id=1<IFRAMESRC="javascript:alert('XSS');"></IFRAME>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 08 Dec 2009 09:38:55 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
SEXO COM A news for c sssh WWW. www.102030 news for c Hry t234t sexwwe 200 /compo www.lolywo Amazingind aniamal s MS06-036 www.sex.bd www.gztaox %252525252 Animalporn WWW.sex.co SEXI VIDEO www.gogal. winxp cras argosoft m hotphotose women and www.sexyta Myspace.Co FrontPage Naruto dan www,lankax www.sexitv xaraya-1.1 sisterxxx w w w.89.c Www.sexyph www.Sexysc Adelphia . t886t dick.com w.w.w.goog components www.halifa Www.18sexy e-gallery newsfilter aks girl /search/ex SEQURITVDO woldsex.co Flm bokep