[29651] in bugtraq

home help back first fref pref prev next nref lref last post

AspJar guestbook script injection vulnerability.

daemon@ATHENA.MIT.EDU (drG4njubas)
Fri Apr 4 14:24:03 2003

From: "drG4njubas" <drG4nj@mail.ru>
To: <bugtraq@securityfocus.com>
Date: Fri, 4 Apr 2003 18:00:59 +0400
Message-ID: <000d01c2fab2$a1920820$9880763e@user1>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="koi8-r"
Content-Transfer-Encoding: 7bit

This advisory and other useful files 
can  be found at  www.blcktigerz.org

Subject:
AspJar guestbook script injection vulnerability.

Description:
Free Advanced ASP Guestbook Script

Vendor:
http://www.aspjar.com

Vulnerability:
guest.asp neglects filtering user input allowing 
for script injection to the guestbook via "URL" 
field. The injected script will be executed in 
anyones browser who visits the guestbook.

____________________________
Best Regards,   drG4njubas
Black Tigerz Research Group
http://www.blacktigerz.org


home help back first fref pref prev next nref lref last post