|
lostBook contains a flaw that allows a remote attacker to inject arbitrary Javascript code. This flaw exists because the application does not validate user-supplied input to the 'email' and 'website' fields before being included in guest book entries. This could allow a remote attacker to create a specially crafted URL that would execute arbitrary Javascript code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|