Cross-Site Scripting Vulnerabilities in DMSGuestbook Plugin for WordPress
CVE-2008-0617
Currently unrated
What is CVE-2008-0617?
The DMSGuestbook 1.7.0 plugin for WordPress is affected by multiple Cross-Site Scripting (XSS) vulnerabilities, which allow remote attackers to inject arbitrary web scripts or HTML into the application. Exploitation occurs through the 'file' parameter in wp-admin/admin.php, the 'messagefield' parameter on the guestbook page, and the 'title' parameter in the message area. This vulnerability can lead to unauthorized access and potentially harmful activities on affected WordPress sites.