Ziyaretçi Defteri "isim" and "mesaj" Script Insertion Vulnerabilities
Thursday, 9 August 2007Description:
GeFORC3 has discovered some vulnerabilities in Ziyaretçi Defteri, which can be exploited by malicious people to conduct script insertion attacks.
Input passed to the "isim" and "mesaj" parameters in save.asp are not properly sanitised before being stored. This can be exploited to insert arbitrary HTML and script code, which is executed in an administrator's browser session in the context of an affected site when the malicious data is viewed.
The vulnerabilities are confirmed in version 1.0. Other versions may also be affected.
Solution:
Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by:
GeFORC3
http://secunia.com/advisories/26375/
Share this content:
|