4.3
CVSSv2

CVE-2003-1348

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote malicious users to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.

Vulnerable Product Search on Vulmon Subscribe to Product

ftls guestbook 1.1

Exploits

source: wwwsecurityfocuscom/bid/6686/info Guestbook does not adequately filter HTML tags from various fields This may enable an attacker to inject arbitrary script code into pages that are generated by the guestbook The attacker's script code may be executed in the web client of arbitrary users who view the pages generated by the guest ...