Cross-site scripting (XSS) vulnerability in view.php in TuttoPhp (1) Morris Guestbook 1, (2) Pretty Guestbook 1, and (3) Smile Guestbook 1 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the pagina parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Morris_guestbook | Tuttophp | * | * |
Pretty_guestbook | Tuttophp | * | * |
Smile_guestbook | Tuttophp | * | * |