Cross-site scripting (XSS) vulnerability in GuestbookXL 1.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an IMG tag in a comment field to (1) guestwrite.php or (2) guestbook.php.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2006-05/0526.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26689 | vdb entry |
http://securityreason.com/securityalert/1017 | third party advisory |