CVE-2005-4879
Jax Guestbook 3.1, 3.31, 3.50 - Cross-Site Scripting via gmt_ofs and language Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4879. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Jax Guestbook due to improper input sanitization. The PoC URL injects arbitrary JavaScript code via the 'language' parameter, which executes in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is also affected.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Jax Guestbook due to improper input sanitization. The PoC URL injects arbitrary JavaScript code via the 'language' parameter, which executes in the context of the affected site.