FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt | patch vendor advisory broken link |
http://marc.info/?l=bugtraq&m=107107840622493&w=2 | mailing list |