AOH :: Web :: Guestbooks :: C07-1077.HTM

@lex Guestbook 4.0.1 : Full Path Disclosure & XSS

@lex Guestbook 4.0.1 : Full Path Disclosure & XSS
@lex Guestbook 4.0.1 : Full Path Disclosure & XSS



@lex Guestbook 4.0.1
--------------------
Vendor site: http://www.alexphpteam.com/ 
Product: @lex Guestbook 4.0.1
Vulnerability: Full Path Disclosure & XSS
Credits: Mr_KaLiMaN
Reported to Vendor: 24.11.06
Public disclosure: 30.11.06
 
Description:
------------
Full Path Disclosure:
http://[victim]/[guestbook_path]/index.php?skin=[non-existent_skin] 
 
XSS:
http://[victim]/[guestbook_path]/index.php?skin=[XSS] 


The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.