CVE-2002-0948

Scripts For Educators MakeBook <2.2 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0948. PoCs published by b0iler.

AI-analyzed exploit summary The exploit demonstrates HTML and SSI injection vulnerabilities in MakeBook guestbook software due to insufficient input sanitization. It provides examples of arbitrary HTML and Server-Side Includes (SSI) injection, which could lead to XSS or command execution depending on the server configuration.

Description

Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.

Exploits (1)

exploitdb WRITEUP VERIFIED
by b0iler · textwebappscgi
https://www.exploit-db.com/exploits/21535

The exploit demonstrates HTML and SSI injection vulnerabilities in MakeBook guestbook software due to insufficient input sanitization. It provides examples of arbitrary HTML and Server-Side Includes (SSI) injection, which could lead to XSS or command execution depending on the server configuration.

Classification
Writeup 90%
Attack Type
Xss | Other
Complexity
Trivial
Reliability
Theoretical
Target: MakeBook guestbook software
No auth needed
Prerequisites: Access to the guestbook form
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4996
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-06/0094.html
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9356.php
Various Sources x_refsource_confirm
http://www.tesol.net/scriptmail.html
Various Sources mailing-list x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2002/06/msg00135.html

Scores

EPSS 0.0763
EPSS Percentile 93.8%

Details

Status published
Products (1)
scripts_for_educators/makebook 2.2
Published Oct 04, 2002
Tracked Since Feb 18, 2026