VulnerabilityModified
CVE-2006-2837
Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book allows remote attackers to inject arbitrary web script or HTML via certain comment fields in the "Sign Our GuestBook" page, probably the x_Comments parameter to guestbookadd.asp.
MEDIUM 4.3EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book allows remote attackers to inject arbitrary web script or HTML via certain comment fields in the "Sign Our GuestBook" page, probably the x_Comments parameter to guestbookadd.asp.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- techno dreams/techno dreams guest book
- Source
- cve@mitre.org
References
- http://colander.altervista.org/advisory/TDGuestBook.txt
- http://secunia.com/advisories/20403Vendor Advisory
- http://www.securityfocus.com/bid/18210
- http://www.vupen.com/english/advisories/2006/2079
- http://colander.altervista.org/advisory/TDGuestBook.txt
- http://secunia.com/advisories/20403Vendor Advisory
- http://www.securityfocus.com/bid/18210
- http://www.vupen.com/english/advisories/2006/2079
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.