PT-2008-2242 · Dmssoftware · Dmsguestbook

Nbbn

·

Published

2008-02-06

·

Updated

2023-08-02

·

CVE-2008-0617

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DMSGuestbook version 1.7.0
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the "file" parameter to "wp-admin/admin.php", the "messagefield" parameter in the guestbook page, or the "title" parameter in the message area.
Recommendations For DMSGuestbook version 1.7.0, consider disabling the plugin until a patch is available to prevent exploitation. Restrict access to the "wp-admin/admin.php" endpoint, and avoid using the file, messagefield, and title parameters in the affected areas until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2008-0617

Affected Products

Dmsguestbook