[<prev] [next>] [day] [month] [year] [list]
Message-ID: <000001c2fce4$4293f110$3b8b763e@user1>
Date: Mon, 7 Apr 2003 13:01:13 +0400
From: "drG4njubas" <drG4nj@...l.ru>
To: <bugtraq@...urityfocus.com>
Subject: Orplex guestbook script injection.
This advisory and other useful files can
be found at http://www.blacktigerz.org
Date:
07.04.2003
Subject:
Orplex guestbook script injection.
Description:
Free asp guestbook. Main fetures are:inserting
smiles as icons; web-based administration; bad word
filtering.
Vendor:
Orplex consulting inc.
http://www.orplex.com
Vulnerability:
addentry.asp neglects filtering user input allowing
for script injection to the guestbook via "Name"
and "Massage" fields. The injected script will be
executed in anyones browser who visits the guestbook.
Black Tigerz Research Group
We are:Areus,Barracuda,n1Tr0f4n,Velzevol,drG4njubas.
Please visit our website: http://www.blacktigerz.org
Powered by blists - more mailing lists