CVE-2008-6359
Max's Guestbook - Cross-Site Scripting via Name Email or Message Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6359. PoCs published by n0tch.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Maxs Guestbook 1.0, including Local File Inclusion (LFI), Persistent XSS, and Full Path Disclosure (FPD). The PoC provides clear examples of exploit vectors without requiring authentication.
Description
Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Maxs Guestbook 1.0, including Local File Inclusion (LFI), Persistent XSS, and Full Path Disclosure (FPD). The PoC provides clear examples of exploit vectors without requiring authentication.