CVE-2006-1697: XSS
Published Apr 11, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message.
Affected Software
1 affected component
Matt Wright Matt Wright Guestbook<=2.3.1
Event History
Apr 11, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1697?
CVE-2006-1697 has a moderate severity level due to its cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2006-1697?
To fix CVE-2006-1697, upgrade Matt Wright Guestbook to a newer version that addresses this vulnerability.
3
Who is affected by CVE-2006-1697?
Users of Matt Wright Guestbook version 2.3.1 and below are affected by CVE-2006-1697.
4
What type of vulnerability is CVE-2006-1697?
CVE-2006-1697 is a cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary scripts.
5
What can attackers do using CVE-2006-1697?
Attackers can exploit CVE-2006-1697 to execute arbitrary web scripts or HTML in the context of the affected user's browser.