CVE-2008-0617
DMSGuestbook 1.7.0 - Cross-Site Scripting via File Parameter or Message Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0617. PoCs published by NBBN.
AI-analyzed exploit summary This is a technical writeup detailing multiple vulnerabilities in WordPress Plugin dmsguestbook 1.7.0, including file disclosure, XSS, and SQL injection. It provides specific exploit URLs, vulnerable code snippets, and attack vectors.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea.
Exploits (1)
This is a technical writeup detailing multiple vulnerabilities in WordPress Plugin dmsguestbook 1.7.0, including file disclosure, XSS, and SQL injection. It provides specific exploit URLs, vulnerable code snippets, and attack vectors.