Winn Guestbook vulnerabilities
2 known vulnerabilities affecting winn/winn_guestbook.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2011-5026P4MEDIUMCVSS 4.3PoC≤ 2.4.8cv2.4.1+7 more2011-12-29
CVE-2011-5026 [MEDIUM] CWE-79 CVE-2011-5026: Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn Guest
Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.
nvd
CVE-2009-4678P4MEDIUMCVSS 4.3PoCv2.42010-03-08
CVE-2009-4678 [MEDIUM] CWE-79 CVE-2009-4678: Cross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers
Cross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
nvd