Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Web :: Guestbooks :: b06-2017.htm

bigwebmaster guestbook multiply XSS



bigwebmaster guestbook multiply XSS
bigwebmaster guestbook multiply XSS



This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enigF3B07DBB015E30AC4D5CC961
Content-Type: text/plain; charset=windows-1251
Content-Transfer-Encoding: quoted-printable

Affected software:
Bigwebmaster Guestbook version 1.02 and down
Vendor:
http://www.bigwebmaster.com/Perl/Scripts_and_Programs/Guestbooks/ 
Introduction:
(taken from vendor site)
This is one of the most powerful guestbooks that you will find on the
internet. Visitors who come to your site will be able to leave comments
and other general information about themselves. If you want to know what
your visitors are thinking, and if you want a fully customizable script,
this one is perfect for you. Features include template files to fit any
website design, 9 standard fields, 9 extra fields (customizable),
unlimited entries, and easy to use admin area. Full online demo available=2E


Vulnerability Details:
when adding a comment addguest.cgi accepts javascript code into
mail,site,city,state and country fields which lead to javascript cross
site scripting when viewguest.cgi is accessed for displaying the content
of the guest book.

POC:
http://www.example.com/gb/addguest.cgi 
name: xss
mail: xss@example.com  
site: http://www.example.com/  
city: 
state: 
country: 

google search:
intitle:Big Webmaster Guestbook

Vendor Status:
NOT NOTIFIED

Solution:
I DON'T CARE

Javor Ninov aka DrFrancky
http://www.securitydot.net/ 


--------------enigF3B07DBB015E30AC4D5CC961
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (MingW32)

iD8DBQFEWiWDck4kcwaj+YIRApunAJ0Vz6d/OEVQNfuiyy3gVa7GwmyuVgCeOAs2
nHeXxQltIZL+kt8vgdOtCIM=HZqy
-----END PGP SIGNATURE-----

--------------enigF3B07DBB015E30AC4D5CC961--


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH