CVE-2011-5026
Published Dec 29, 2011
Last updated 7 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:winn:winn_guestbook:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF6B3B24-BD80-4470-8984-F773C3DF367E", "versionEndIncluding": "2.4.8c" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.1:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BD4F0A3-E9F8-4508-BBF1-9596F198AEA8" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0057BB5C-5FF3-4098-A0CF-C723EDF5E0C8" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C1BB1F3-C077-4E34-9BC6-4B87B1CBD6B0" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "300C4CA8-D47F-43ED-977D-2458CF35D466" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B8FD2B2-8A27-48D1-93A7-B7E25DD39436" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF44D32D-2020-41EA-9C69-8B805E1E3435" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E14FA76E-50B4-4930-B9A4-6E761CCD55DD" }, { "criteria": "cpe:2.3:a:winn:winn_guestbook:2.4.8b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1BAB3B8D-CB4D-427D-A6AB-30E185EB070D" } ], "operator": "OR" } ] } ]