Ben's Guestbook Cross Site Scripting Vulnerability
9 Dec. 2003
Summary
Ben's guestbook is "a simple guestbook that allows your visitors to leave the persons name, email, and comments that they would like to add. This guestbook does not use MySQL so it will work if you don't have MySQL". A vulnerability in the product allows remote attackers to inject HTML and/or JavaScript into pages showed to arbitrary users.