CVE-2002-2339
Script-Shed GuestBook 1.0 - Cross-Site Scripting via JavaScript URL in Image Tags
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-2339. PoCs published by frog.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in SSGbook guestbook software by injecting malicious JavaScript code within image tags. The attacker-supplied code executes when a user views the malicious guestbook entry.
Description
Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left tags.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in SSGbook guestbook software by injecting malicious JavaScript code within image tags. The attacker-supplied code executes when a user views the malicious guestbook entry.