Vulnerabilities > CVE-2005-1620 - Unspecified vulnerability in Soren Boysen Skull-Splitter Guestbook 1.0/2.0/2.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Skull-Splitter Guestbook 1.0/2.0/2.2 Multiple HTML Injection Vulnerabilities. CVE-2005-1620. Webapps exploit for php platform |
id | EDB-ID:25662 |
last seen | 2016-02-03 |
modified | 2005-05-14 |
published | 2005-05-14 |
reporter | Morinex Eneco |
source | https://www.exploit-db.com/download/25662/ |
title | Skull-Splitter Guestbook 1.0/2.0/2.2 - Multiple HTML Injection Vulnerabilities |
Nessus
NASL family | CGI abuses : XSS |
NASL id | SKULLSPLITTER_HTML_INJECTION.NASL |
description | The remote version of this software is vulnerable to cross-site scripting attacks. Inserting special characters into the subject or message content can cause arbitrary script code execution for third-party users, thus resulting in a loss of integrity of their system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18265 |
published | 2005-05-16 |
reporter | Copyright (C) 2005-2018 Josh Zlatin-Amishav |
source | https://www.tenable.com/plugins/nessus/18265 |
title | Skull-Splitter Guestbook Multiple Field XSS |
code |
|