Orplex guestbook script injection.

From: drG4njubas (drG4njat_private)
Date: Mon Apr 07 2003 - 02:01:13 PDT

  • Next message: Conectiva Updates: "[CLA-2003:620] Conectiva Security Announcement - man"

    This advisory and other useful files can
    be found at http://www.blacktigerz.org
    
    
    Date:
    07.04.2003
    
    Subject:
    Orplex guestbook script injection.
    
    Description:
    Free asp guestbook. Main fetures are:inserting 
    smiles as icons; web-based administration; bad word 
    filtering.
    
    Vendor:
    Orplex consulting inc.
    http://www.orplex.com
    
    Vulnerability:
    addentry.asp neglects filtering user input allowing 
    for script injection to the guestbook via "Name" 
    and "Massage" fields. The injected script will be 
    executed in anyones browser who visits the guestbook.
    
    
    Black Tigerz Research Group
    We are:Areus,Barracuda,n1Tr0f4n,Velzevol,drG4njubas.
    Please visit our website: http://www.blacktigerz.org 
    



    This archive was generated by hypermail 2b30 : Tue Apr 08 2003 - 09:50:07 PDT