[29651] in bugtraq
AspJar guestbook script injection vulnerability.
daemon@ATHENA.MIT.EDU (drG4njubas)
Fri Apr 4 14:24:03 2003
From: "drG4njubas" <drG4nj@mail.ru>
To: <bugtraq@securityfocus.com>
Date: Fri, 4 Apr 2003 18:00:59 +0400
Message-ID: <000d01c2fab2$a1920820$9880763e@user1>
MIME-Version: 1.0
Content-Type: text/plain;
charset="koi8-r"
Content-Transfer-Encoding: 7bit
This advisory and other useful files
can be found at www.blcktigerz.org
Subject:
AspJar guestbook script injection vulnerability.
Description:
Free Advanced ASP Guestbook Script
Vendor:
http://www.aspjar.com
Vulnerability:
guest.asp neglects filtering user input allowing
for script injection to the guestbook via "URL"
field. The injected script will be executed in
anyones browser who visits the guestbook.
____________________________
Best Regards, drG4njubas
Black Tigerz Research Group
http://www.blacktigerz.org