First published: Tue Apr 11 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it is likely that they are the result of post-disclosure analysis.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matt Wright Guestbook | <=2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1698 has a moderate severity rating due to the potential for attackers to execute arbitrary web scripts.
To fix CVE-2006-1698, upgrade to a version of Matt Wright Guestbook that is not vulnerable, specifically later than 2.3.1.
CVE-2006-1698 affects Matt Wright Guestbook versions up to and including 2.3.1.
CVE-2006-1698 allows for cross-site scripting (XSS) attacks which can execute harmful scripts in a user's browser.
Remote attackers can exploit CVE-2006-1698 through the vulnerable URL, city, state, or country parameters.