Kv Guestbook Cross-Site Scripting...

- AV AC AU C I A
发布: 2002-04-27
修订: 2025-04-13

Kv Guestbook is a web based guest book message board maintained by KillerVault. Kv Guestbook does not filter script code from URL parameters, making it prone to cross-site scripting attacks. Attacker-supplied script code may be included in a malicious link to the 'guestbook.php' script. Such a malicious link might be included in a HTML e-mail or on a malicious webpage. This may enable a remote attacker to steal cookie-based authentication credentials from legitimate users of Kv Guestbook.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息