Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage, (2) mail, and (3) name parameters in a show action to (a) form.php; the (4) language and (5) anzeigebreite parameters to (b) admin/header.php; and the (6) msg parameter to (c) install.php, different vectors than CVE-2006-0706.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/478803/100/0/threaded | mailing list |
http://www.osvdb.org/36736 | vdb entry |
http://securityreason.com/securityalert/3097 | third party advisory |
http://www.securityfocus.com/archive/1/478360/100/0/threaded | mailing list |
http://secunia.com/advisories/26662 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36404 | vdb entry |
http://www.securityfocus.com/bid/25507 | patch vdb entry exploit |
http://www.osvdb.org/36735 | vdb entry |