CVE-2007-1479
Creative Guestbook 1.0 - Cross-Site Scripting in Guestbook.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1479. PoCs published by Dj7xpl.
AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in Creative Guestbook 1.0: a stored XSS vulnerability in the guestbook entry field and an unauthorized admin user creation flaw via direct POST requests to createadmin.php. The PoC includes HTML forms and endpoints to trigger both issues.
Description
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Exploits (1)
This exploit demonstrates two vulnerabilities in Creative Guestbook 1.0: a stored XSS vulnerability in the guestbook entry field and an unauthorized admin user creation flaw via direct POST requests to createadmin.php. The PoC includes HTML forms and endpoints to trigger both issues.