PT-2007-1193 · Dt · Dm Guestbook
Jesper Jurcenoks
·
Published
2007-01-16
·
Updated
2018-10-17
·
CVE-2006-6487
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
DT Guestbook version 1.0f
Description:
A cross-site scripting issue exists due to the lack of proper input validation in the index.php file of DT Guestbook. When the register globals setting is enabled, remote attackers can inject arbitrary web script or HTML via the
error[] parameter.Recommendations:
For DT Guestbook version 1.0f, consider disabling the register globals setting to prevent exploitation. Additionally, restrict access to the index.php file until a proper fix is applied, and avoid using the
error[] parameter in sensitive operations.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dm Guestbook