============================================================ ============================================================ Title: Guestbook PRO Vulnerability discovery: SoulBlack - Security Research - http://soulblack.com.ar Date: 10/05/2005 Severity: Medium. defacement website Affected version: <= v3.2.1 vendor: PixySOft. ============================================================ ============================================================ * Summary * Guestbook PRO is an advanced guestbook for WebApp. ------------------------------------------------------------------------------------------------------------------------ * Problem Description * A new vulnerability is in the content and title of msg, when not controlling the entrance of characters, being able to inject HTML code. ------------------------------------------------------------------------------------------------------------------------ * Example * Type in the title or content of msg