the internet's safety

advisory-realGuestbook_V5-en.txt

advisory-realGuestbook_V5-en.txt
Posted Mar 28, 2007
Authored by Ruben Ventura Pina | Site trew.icenetx.net

realGuestbook_V5 suffers from a HTML injection vulnerability.

tags | exploit
MD5 | 36992e869809a12a3a00804ff3eaffce

advisory-realGuestbook_V5-en.txt

Change Mirror Download
--------------------------------------------------------
realGuestbook_V5 Script Injection Vulnerability |
Discovered by Trew | ICEnetX Team http://icenetx.net |
http://trew.icenetx.net trew.revolution@gmail.com |
--------------------------------------------------------

Date: 17 march 2007
Vendor URL: http://realscripts.de
Risk: Medium
Satatus: Unpatched

## Vulnerability ##

realGuestbook_V5 is a German Guestbook system. This guestbooks may allow an attacker to inject code into the page. The injection is achieved through injecting code into the homepage field, some administrators decide to delete this field, but the original version of the aplication includes this field.

The vulnerability is located in the page where comments are sent (default: add_entry.php). This is the
vulnerable field:

<input type="text" name="hoempage" style="width:100%" value=" INYECTION GOES HERE ">

The 'homepage' variable is not santized correctly, so code can be injected by breaking the link tag generated in
guestbook.php, by writting the characters "> at the beggining of the URL field.

Attack example:

URL value: url = http://trew.icenetx.net
Result in guestbook.php: <a href="http://trew.icenetx.net">...

URL value: url = "><h1>HACKED</h1>
Resultin guestbook.php: <a href=""><h1>HACKED</h1> ...

## How to fix ##

Filter or delete the URL field at add_entry.php

-----
"Maybe you can't break the system, but you can always hack it."
http://trew.icenetx.net trew.revolution@gmail.com

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close