CVE-2006-2837 Information

Description

Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book allows remote attackers to inject arbitrary web script or HTML via certain comment fields in the \Sign Our GuestBook\ page probably the x_Comments parameter to guestbookadd.asp.

Reference

http://colander.altervista.org/advisory/TDGuestBook.txt http://secunia.com/advisories/20403 http://www.securityfocus.com/bid/18210 http://www.vupen.com/english/advisories/2006/2079

Share on: