CVE-2003-1348
ftls guestbook 1.1 - Cross-Site Scripting via Comment Name or Title Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1348. PoCs published by BrainRawt.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Guestbook software by injecting arbitrary HTML/JS code into the Title, Name, and Comment fields. The PoC shows how an attacker can execute script code in the context of users viewing the guestbook.
Description
Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Guestbook software by injecting arbitrary HTML/JS code into the Title, Name, and Comment fields. The PoC shows how an attacker can execute script code in the context of users viewing the guestbook.