Cross-Site Scripting Vulnerabilities in Carbonize Lazarus Guestbook by Carbonize
CVE-2006-3616

Currently unrated

Key Information:

Vendor

Carbonize

Vendor
CVE Published:
18 July 2006

What is CVE-2006-3616?

The Carbonize Lazarus Guestbook, version 1.6 and earlier, contains multiple cross-site scripting (XSS) vulnerabilities that can be exploited by remote attackers. These vulnerabilities allow attackers to inject arbitrary web scripts or HTML through the 'show' parameter in codes-english.php and the 'img' parameter in picture.php, provided they include the name of an existing file. Successful exploitation could lead to unauthorized access or manipulation of user data, posing significant risks to the security and integrity of the affected web applications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.