PT-2006-2691 · Matt Wright · Matt Wright Guestbook

Liz0Zim

·

Published

2006-04-11

·

Updated

2018-10-18

·

CVE-2006-1697

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Matt Wright Guestbook version 2.3.1
Description: A cross-site scripting (XSS) issue allows remote attackers to execute arbitrary web script or HTML via the Your Name, E-Mail, or Comments fields when posting a message.
Recommendations: For Matt Wright Guestbook version 2.3.1, consider disabling the posting of messages until a patch is available to prevent exploitation of the XSS issue. Restrict access to the fields Your Name, E-Mail, and Comments to minimize the risk of arbitrary web script or HTML execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1697

Affected Products

Matt Wright Guestbook