AspJar guestbook script injection vulnerability.

From: drG4njubas (drG4njat_private)
Date: Fri Apr 04 2003 - 06:00:59 PST

  • Next message: KF: "[VulnWatch] SRT2003-04-04-1106 - AOLServer Proxy Daemon API unformatted syslog() call"

    This advisory and other useful files 
    can  be found at  www.blcktigerz.org
    
    Subject:
    AspJar guestbook script injection vulnerability.
    
    Description:
    Free Advanced ASP Guestbook Script
    
    Vendor:
    http://www.aspjar.com
    
    Vulnerability:
    guest.asp neglects filtering user input allowing 
    for script injection to the guestbook via "URL" 
    field. The injected script will be executed in 
    anyones browser who visits the guestbook.
    
    ____________________________
    Best Regards,   drG4njubas
    Black Tigerz Research Group
    http://www.blacktigerz.org
    



    This archive was generated by hypermail 2b30 : Fri Apr 04 2003 - 11:23:33 PST