CGI-City's CCGuestBook Script Injection Vulns

From: BrainRawt . (brainrawtat_private)
Date: Sat Mar 29 2003 - 10:47:04 PST

  • Next message: BrainRawt .: "CGI-City's CCLOG Script Injection Vulns"

    CGI-City's CCGuestBook Script Injection Vulnerabilities
    Discovered By BrainRawt (brainrawtat_private)
    
    About CCGuestBook:
    ------------------
    CC Guestbook is a simple guestbook program that is very easy
    to configure and install. It features a notification facility
    which sends an email alert to the guestbook owner whenever new
    entries are made. It may also be used as a post-it board to
    allow visitors to a web site to just post messages.
    
    CCGuestBook can be downloaded from the following address.
    
    http://www.icthus.net/CGI-City/scr_cgicity.shtml#CCGUEST
    
    
    Vendor Contact:
    ----------------
    1-30-03 Emailed cgicityat_private
    
    No Response
    
    Vulnerability:
    ----------------
    cc_guestbook.pl neglects filtering user input allowing for script
    injection to the guestbook via "name" and "webpage title".  The
    injected script will be executed in anyones browser who visits
    the guestbook.
    
    
    Exploit (POC):
    ----------------
    <script>alert('obvious?')</script>
    
    
    
    
    
    
    
    _________________________________________________________________
    Protect your PC - get McAfee.com VirusScan Online  
    http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963
    



    This archive was generated by hypermail 2b30 : Sat Mar 29 2003 - 12:04:15 PST