[40863] in bugtraq

home help back first fref pref prev next nref lref last post

Zomplog Script Injection Vulnerability =>3.4 (all versions

daemon@ATHENA.MIT.EDU (sikikmail@gmail.com)
Mon Oct 24 17:48:34 2005

Date: 22 Oct 2005 13:25:23 -0000
Message-ID: <20051022132523.11408.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: sikikmail@gmail.com
To: bugtraq@securityfocus.com

zomplog is prone to xss injection attacks. It is possible for a malicious zomplog user to inject hostile xss and script code into the commentary via form fields. This code may be rendered in the browser of a web user who views the commentary of zomplog.
zomplog does not adequately filter xss tags from various fields. This may enable an attacker to inject arbitrary script code into pages that are generated by the blog.
example:
put <script>alert('test')</script> in http://localhost/zomplog/detail.php?id=1#comments

Zamplog home page: http://zomplog.zomp.nl/


home help back first fref pref prev next nref lref last post