CVE Database
/

CVE-2005-4649

Back to search

CVE-2005-4649

Published: Jan 13, 2006

Modified: Sep 16, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from CVE-2005-1548.

VendorProductVersions

n/a

n/a

affected
n/a

References

20051225 Advanced Guestbook remote XSS exploit
mailing-list
x_refsource_FULLDISC
22188
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now