Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [Full-disclosure] deV!L`z Clanportal - Arbitrary File Upload [061124b]

  [Full-disclosure] phpmyfaq exploit using PHP bug, CVE-2006-1490

  Invision Gallery  2.0.7 SQL Injection Vulnerability

  LifeType version 1.1.2 Multiple Path Disclosure Vulnerabilities

From:Mr_KaLiMaN <mr_kaliman_(at)_msn.com>
Date:01.12.2006
Subject:@lex Guestbook 4.0.1 : Full Path Disclosure & XSS

@lex Guestbook 4.0.1
--------------------
Vendor site: http://www.alexphpteam.com/
Product: @lex Guestbook 4.0.1
Vulnerability: Full Path Disclosure & XSS
Credits: Mr_KaLiMaN
Reported to Vendor: 24.11.06
Public disclosure: 30.11.06

Description:
------------
Full Path Disclosure:
http://[victim]/[guestbook_path]/index.php?skin=[non-existent_skin]

XSS:
http://[victim]/[guestbook_path]/index.php?skin=[XSS]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server