about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Advanced Guestbook Picture.PHP Cross-Site Scripting Vulnerability


Title Advanced Guestbook Picture.PHP Cross-Site Scripting Vulnerability
Published 2007-05-08-12:00AM
Updated 2007-05-08-05:09PM
Class Input Validation Error
CVE   CVE-2007-0605
Remote  Yes
Local  No
Credit  Jesper Jurcenoks is credited with the discovery of this vulnerability.
Vulnerable  Advanced Guestbook Advanced Guestbook 2.4.2
Not Vulnerable  
Code   An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.

The following proof-of-concept URI is available:

http://www.example.com/picture.php?size[0]=1&size[1]=1&img=1&picture=[xss]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 29 Nov 2009 06:45:51 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
. cutenews 200 /compo WWW.89.CM. mambo remo What\'s th CMS is F.. indiyan se tt.365hang nude bolly www.66q.co Symantec M news for c news for c www.586.me www.v2jw.c 2.6 local gkbfb.com l...e.php? MySQL 5.1. www.zgrjrc www.ku518. zoo video FREESEX 3G crian Homosexpho telephony www.lvshul Www.antarv porni& indiansexp phpbb 2.0. Www.sexvie m...l/comp /component free downl www.sex.am Rakhi in s sex gerils classified guest book hugointens nanga+kere Google Ana LOGO benazir se Www.phoner www.pink w news for c www.k6chin