EJ3 BlackBook HTML Injection Vulnerability...

- AV AC AU C I A
发布: 2003-07-14
修订: 2025-04-13

EJ3 BlackBook does not filter script code from many input fields used to accept guestbook signature information, making it prone to HTML injection attacks. Attacker-supplied script code may be included in fields submitted in the 'sign.php' script. This may enable a remote attacker to steal cookie-based authentication credentials from legitimate users of BlackBook.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息