|
vlBook 1.02 Advisory
====================
Date:
-----
2005 June 23
Product:
--------
vlBook 1.02 =A9 2005
Vendor:
-------
http://vlab.info/
Descriptions:
-------------
The vlbook is a free, open source and light-weight guestbook written in PHP using flat files to store messages
and settings. It comes with install script for quick and effortless installation. Features include a WYSIWYG Editor,
template based skins, multilingual support, avatars packs and more.
Exploit(s)/Vulnerability(ies):
------------------------------
- XSS Vulnerability -
This product is vulnerable to an XSS Attack. The variable message is not properly sanitised before being used; so a malicious
people can inject arbitrary XSS code.
PoC 0f XSS:
-----------
If an attacker put in the field "Message*:" this code:
Further information:
--------------------
googledorks: Powered by vlBook 1.02 =A9 2005
Vendor Status:
--------------
Informed but I've not received the reply.
Credits:
--------
Omnipresent
omnipresent@email.it