Vulnerabilities > Matt Wright > Matt Wright Guestbook

DATE CVE VULNERABILITY TITLE RISK
2006-04-11 CVE-2006-1698 Cross-Site Scripting vulnerability in Matt Wright Guestbook
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters.
network
matt-wright
4.3
2006-04-11 CVE-2006-1697 HTML Injection vulnerability in Matt Wright Guestbook Guestbook.PL
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message.
network
matt-wright
4.3
1999-09-13 CVE-1999-1053 Remote Command Execution vulnerability in Guestbook CGI
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
network
low complexity
apache matt-wright
7.5