Multiple XSS in GBook PHP guestbook

2011-07-27 Thread advisory
Vulnerability ID: HTB23028 Reference: http://www.htbridge.ch/advisory/multiple_xss_in_gbook_php_guestbook.html Product: GBook PHP guestbook Vendor: PHPJunkyar ( http://www.phpjunkyard.com ) Vulnerable Version: 1.7 and probably prior Tested on: 1.7 Vendor Notification: 06 July 2011 Vulnerability

More info: gBook Multiple Unspecified Cross-Site Scripting Vulnerabilities

2006-02-20 Thread mkproductions
Some additional information about http://www.securityfocus.com/bid/14725 has been disclosed. http://gbook.sourceforge.net/sec/14725

gBook

2002-10-22 Thread Frog Man
Informations : °° Language : PHP Tested version : 1.4 Problem : Admin access PHP Code : °° /gb/index.php : -- include("config.inc.php"); if($action == "login") { if($user == $loginu && $pw == $loginpw) { setcookie("login