Ftls.Org · Ftls.Org Guestbook · CVE-2003-1348
**Name of the Vulnerable Software and Affected Versions**
ftls.org Guestbook version 1.1
**Description**
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `comment`, `name`, or `title` field in the guestbook.cgi script.
**Recommendations**
For ftls.org Guestbook version 1.1, consider validating and sanitizing user input for the `comment`, `name`, and `title` fields to prevent XSS attacks. As a temporary workaround, restrict access to the guestbook.cgi script until a proper fix is applied.