Vulnerabilities > CVE-2004-1867 - HTML Injection vulnerability in Web Fresh Fresh Guest Book 1.0/2.0/2.1

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
web-fresh
exploit available

Summary

Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.

Vulnerable Configurations

Part Description Count
Application
Web_Fresh
3

Exploit-Db

descriptionFresh Guest Book 1.0/2.x HTML Injection Vulnerability. CVE-2004-1867. Webapps exploit for cgi platform
idEDB-ID:23890
last seen2016-02-02
modified2004-03-29
published2004-03-29
reporterkoi8-r Shelz
sourcehttps://www.exploit-db.com/download/23890/
titleFresh Guest Book 1.0/2.x HTML Injection Vulnerability