GuppY 2.4 – HTML Injection

28次阅读
没有评论

GuppY 2.4 – HTML Injection

漏洞ID 1054196 漏洞类型
发布时间 2003-09-29 更新时间 2003-09-29
GuppY 2.4 - HTML InjectionCVE编号 N/A
GuppY 2.4 - HTML InjectionCNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/23192
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8717/info

It has been reported that one of the scripts included with GuppY is vulnerable to an HTML injection attack. The script, "postguest.php", does not perform input validation to prevent the inclusion of HTML/script content in messages posted to the portal by remote clients. The flaw is present in the implementation of the "[c]" tag, which can be used by users posting messages in the forum or in the guestbook components of GuppY portals.

The vendor is aware of the vulnerability and has released an updated version, 2,4p1, that eliminates the issue. 

[c=expression(alert('unsecure'))]texte[/c]

相关推荐: AppIdeas MyCart Information Disclosure Vulnerability

AppIdeas MyCart Information Disclosure Vulnerability 漏洞ID 1101010 漏洞类型 Input Validation Error 发布时间 2003-01-09 更新时间 2003-01-09 CVE编…

正文完
 0