7.5
CVSSv2

CVE-2002-0730

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote malicious users to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.

Vulnerable Product Search on Vulmon Subscribe to Product

philip chinery philip chinerys guestbook 1.1

Exploits

source: wwwsecurityfocuscom/bid/4566/info Philip Chinery's Guestbook is freely available guestbook software It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems Philip Chinery's Guestbook does not filter script code from form fields As a result, it is possible for an attacker to inject script cod ...