Open Guestbook 0.5 title tag XSS
Simo64 posted a vulnerability to Bugtraq today, that demonstrated a pretty useful vector. It’s pretty obvious but it’s also not used that often. A TITLE tag is encapsulated with everything other than an end TITLE tag. An end title tag will allow any HTML to be rendered inside of the HEAD tag that it resides.
Simo64 pointed out this vector by popping out of the TITLE tag in the Open Guestbook software, which allowed a cross site scripting vulnerability to render. There’s also an SQL injection vector, which is actually slightly less interesting as it’s a pretty typical SQL injection. Anyway, good job, Simo64!



June 26th, 2006 at 9:34 pm
Highly interesting. Remind me to check my webapps for that one
March 8th, 2008 at 2:09 am
You only look at it
Were issued some piracy photos on which the new model of a mobile phone of company Sony Ericsson is ostensibly represented.
You only look at it:
http://ddosmanager.org/sony/image.jpg