Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Brainrawt

#30461of 53,622
8.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2003-2293
4.3
2003-12-31
Ftls.Org · Ftls.Org Guestbook · CVE-2003-1348
**Name of the Vulnerable Software and Affected Versions** ftls.org Guestbook version 1.1 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `comment`, `name`, or `title` field in the guestbook.cgi script. **Recommendations** For ftls.org Guestbook version 1.1, consider validating and sanitizing user input for the `comment`, `name`, and `title` fields to prevent XSS attacks. As a temporary workaround, restrict access to the guestbook.cgi script until a proper fix is applied.
PT-2003-2501
4.3
2003-12-31
Cc · Cc Guestbook · CVE-2003-1556
**Name of the Vulnerable Software and Affected Versions** CC GuestBook (affected versions not specified) **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `name` and `homepage title` parameters. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.