CVE-2011-5026
29.12.2011, 04:15
Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
winn | winn_guestbook | 𝑥 ≤ 2.4.8c |
winn | winn_guestbook | 2.4.1:beta |
winn | winn_guestbook | 2.4.2 |
winn | winn_guestbook | 2.4.3 |
winn | winn_guestbook | 2.4.4 |
winn | winn_guestbook | 2.4.5 |
winn | winn_guestbook | 2.4.6 |
winn | winn_guestbook | 2.4.7 |
winn | winn_guestbook | 2.4.8b:b |
𝑥
= Vulnerable software versions
References