OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [eVuln] Vanilla Guestbook Multiple XSS & SQL Injection Vulnerabilities

tachyontachyondecay.net
Date: Sun Feb 26 2006 - 20:12:51 CST


I don't really recall receiving any sort of notification about this. . . .

But anyway, I am indeed aware of XSS vulnerabilities in the software. My time has been devoted to overhauling my blog software, however. I hope to seriously rewrite the guestbook script as soon as possible. It _is_ a beta version. That may not be an excuse, but it should at least be a warning. Assuredly I'll make sure to get rid of the XSS vulnerabilities when I rewrite the script pending a final release.