exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

advisory-php-gaestebuch-en.txt

advisory-php-gaestebuch-en.txt
Posted Mar 8, 2007
Authored by Ruben Ventura Pina | Site trew.icenetx.net

PHP-Gaestebuch versions 6.3 and below suffer from a HTML injection vulnerability that can allow for cross site scripting attacks.

tags | exploit, php, xss
SHA-256 | 2e93b4d81779ca64b2a6b178843c2da8f2564aa45d9289efe4ab6618d10fa2cd

advisory-php-gaestebuch-en.txt

Change Mirror Download
--------------------------------------------------------
PHP-Gaestebuch v1.63 Script Injection Vulnerability |
Discovered by Trew | ICEnetX Team http://icenetx.net |
http://trew.icenetx.net trew.revolution@gmail.com |
--------------------------------------------------------

Date: 04 marzo 2007
Vendor URL: http://www.php-gaestebuch.de/
Risk: Medium
Satatus: Unpatched
Vulnerable versions: v6.3 and earlier

## Vulnerability ##

Php-Gaestebuch is a German Guestbook system. This guestbooks may allow an attacker to inject code into the page. The
vulnerable versions are the 6.3 (most recent) and earliers. The injection is achieved through injecting code into the URL
field, some administrators decide to delete this field, but the original version of the aplication includes this field.

The vulnerability is located in the page where comments are sent (default: guestbook_newentry.php). This is the
vulnerable field:

<input id="gbinput" type="text" name="url" size="40" value="INJECTION-GOES-HERE" tabIndex="3">

The 'URL' variable is not santized correctly, and so code can be injected breaking the link tag generated in
guestbook.php, by writting the characters "> at the beggining of the URL field.

Attack example:

URL value: url = http://trew.icenetx.net
Result in guestbook.php: <a href="http://trew.icenetx.net">...

URL value: url = "><h1>HACKED</h1>
Resultin guestbook.php: <a href=""><h1>HACKED</h1> ...

## How to fix ##

Filter or delete the URL field at guestbook_newentry.php

-----
"Maybe you can't break the system, but you can always hack it."
http://trew.icenetx.net trew.revolution@gmail.com
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close