CVE-2009-3328
WX-Guestbook 1.1.208 - Cross-Site Scripting via sName Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3328. PoCs published by learn3r.
AI-analyzed exploit summary This is a technical writeup detailing SQL injection and persistent XSS vulnerabilities in WX Guestbook 1.1.208. It includes specific exploit strings for SQLi and XSS, along with a root cause analysis of unsanitized input.
Description
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.
Exploits (1)
This is a technical writeup detailing SQL injection and persistent XSS vulnerabilities in WX Guestbook 1.1.208. It includes specific exploit strings for SQLi and XSS, along with a root cause analysis of unsanitized input.