The vlbook is a free, open source and light-weight guestbook written in PHP
using flat files to store messages
and settings. It comes with install script for quick and effortless
installation. Features include a WYSIWYG Editor,
template based skins, multilingual support, avatars packs and more.
Exploit(s)/Vulnerability(ies):
------------------------------
- XSS Vulnerability -
This product is vulnerable to an XSS Attack. The variable message is not
properly sanitised before being used; so a malicious
people can inject arbitrary XSS code.
PoC 0f XSS:
-----------
If an attacker put in the field "Message*:" this code:
<script>alert("XSS ATTACK")</script>
Further information:
--------------------
googledorks: Powered by vlBook 1.02 © 2005
Vendor Status:
--------------
Informed but I've not received the reply.
Credits:
--------
Omnipresent
omnipresent (at) email (dot) it [email concealed]
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.