CVE-2009-2440

JNM Guestbook 3.0 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34806

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1831
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35760

Scores

EPSS 0.0100
EPSS Percentile 77.1%

Details

CWE
CWE-79
Status published
Products (1)
jnmsolutions/guestbook 3.0
Published Jul 13, 2009
Tracked Since Feb 18, 2026