Guestbook v1.1.3 CSS Vuln

From: flur (flurat_private)
Date: Fri Mar 14 2003 - 14:22:51 PST

  • Next message: Ken.Williamsat_private: "RE: response to tax software not encrypting tax info"

    Project:   Filebased guestbook.
    Author:    Copyright (c) Urs <ursat_private>
    Version:   1.1.3
    Update:    17-09-2002
    Homepage:  http://www.circle.ch/scripts/
    
    This PHP guest book script is vulnerable to hostile cross scripting in the 
    'comment' section of guest book posts. Comments span across multiple pages, 
    with the newest on the first page- thus a malicious user could easily embed 
    hostile code and expect all that read the guest book with script-processing 
    browsers to execute it.
    
    The vendor has indicated that this project has been discontinued.
    
    
    
    ____________________ __ _
    ~FluRDoInG                        flurat_private
                                 http://www.flurnet.org
    KEY ID 0x8C2C37C4 (pgp.mit.edu) RSA-CAST 2048/2048
    1876 B762 F909 91EB 0C02  C06B 83FF E6C5 8C2C 37C4
    



    This archive was generated by hypermail 2b30 : Fri Mar 14 2003 - 15:20:40 PST