GuppY 2.4 – HTML Injection

GuppY 2.4 – HTML Injection

漏洞ID 1054196 漏洞类型
发布时间 2003-09-29 更新时间 2003-09-29
图片[1]-GuppY 2.4 – HTML Injection-安全小百科CVE编号 N/A
图片[2]-GuppY 2.4 – HTML Injection-安全小百科CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/23192
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8717/info

It has been reported that one of the scripts included with GuppY is vulnerable to an HTML injection attack. The script, "postguest.php", does not perform input validation to prevent the inclusion of HTML/script content in messages posted to the portal by remote clients. The flaw is present in the implementation of the "[c]" tag, which can be used by users posting messages in the forum or in the guestbook components of GuppY portals.

The vendor is aware of the vulnerability and has released an updated version, 2,4p1, that eliminates the issue. 

[c=expression(alert('unsecure'))]texte[/c]

相关推荐: AppIdeas MyCart Information Disclosure Vulnerability

AppIdeas MyCart Information Disclosure Vulnerability 漏洞ID 1101010 漏洞类型 Input Validation Error 发布时间 2003-01-09 更新时间 2003-01-09 CVE编…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享