CVE-2006-1698Cross-site Scripting in Wright Guestbook

3 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.3%
top 43.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it is likely that they are the result of post-disclosure analysis.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-4g8f-f2wr-wmxm: Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 22022-05-01
CVEList
CVE-2006-1698: Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 22006-04-11
CVE-2006-1698 — Cross-site Scripting | cvebase