CVE-2003-0979 Information
Feb 14, 2021
cve
Description
FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input which allows remote attackers to (1) use VisitorBook as an open mail relay when $mailuser is 1 via extra headers in the email field or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.
Reference
http://marc.info/?l=bugtraq&m=107107840622493&w=2 http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt
Share on: