Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Gregarius <= 0.5.4 SQL Injection

  [DSECRG-08-034] Local File Include Vulnerability in Minishowcase v09b136

  HIOX Random Ad 1.3 (hioxRandomAd.
php hm) RFI Vulnerability

  HIOX Browser Statistics 2.0 Remote File Inclusion Vulnerability

From:irancrash_(at)_gmail.com <irancrash_(at)_gmail.com>
Date:30.07.2008
Subject:MJGuest 6.8 GT Cross Site Scripting Vulnerability

----------------------------------------------------------------

Script : MJGuest 6.8 GT

Type : Cross Site Scripting Vulnerability

Alert : Medium

----------------------------------------------------------------

Discovered by : Khashayar Fereidani

Our Team : IRCRASH

My Official Website : HTTP://FEREIDANI.IR

Khashayar Fereidani Email : irancrash [ a t ] gmail [ d o t] com

----------------------------------------------------------------

Khashayar Fereidani Offical Website : HTTP://FEREIDANI.IR

----------------------------------------------------------------

Script Download : http://www.mdsjack.bo.it/files/mjguest_6.8gt.zip

----------------------------------------------------------------
XSS Vulnerability :

Invalid Code : ./guestbook.js.php => document.write('<a href="javascript:guestbook()">' + '<?php
echo $_GET['link']?>' + '</a>');

Vulnerable variable : link

Address : http://Example/guestbook.js.php?link=[XSS]

Solution : Filter link variable with htmlsepcialchars() function .

----------------------------------------------------------------

                       Tnx : God

                    HTTP://IRCRASH.COM

----------------------------------------------------------------

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru