CVE-2011-5026

Winn GuestBook < 2.4.8d - Cross-Site Scripting via Name Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-5026. PoCs published by G13.

AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in Winn Guestbook v2.4.8c due to lack of input sanitization on the 'name' variable. The exploit requires the attacker's email to be in the 'approved posters' list for successful execution.

Description

Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by G13 · textwebappsphp
https://www.exploit-db.com/exploits/18290

This is a writeup describing a stored XSS vulnerability in Winn Guestbook v2.4.8c due to lack of input sanitization on the 'name' variable. The exploit requires the attacker's email to be in the 'approved posters' list for successful execution.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Winn Guestbook v2.4.8c
Auth required
Prerequisites: Attacker's email must be in the 'approved posters' list
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72025
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/78070
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18290
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47391

Scores

EPSS 0.0169
EPSS Percentile 74.1%

Details

CWE
CWE-79
Status published
Products (9)
winn/winn_guestbook 2.4.1 beta
winn/winn_guestbook 2.4.2
winn/winn_guestbook 2.4.3
winn/winn_guestbook 2.4.4
winn/winn_guestbook 2.4.5
winn/winn_guestbook 2.4.6
winn/winn_guestbook 2.4.7
winn/winn_guestbook 2.4.8b
winn/winn_guestbook < 2.4.8c
Published Dec 29, 2011
Tracked Since Feb 18, 2026