Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Guestbox |
Michael_salzer |
0.6 |
0.6 |
References