Description
|
|
A vulnerability has been identified in @lex Guestbook, which could be exploited by attackers to disclose sensitive information or execute arbitrary scripting code. This flaw is due to an input validation error in the "index.php" script when handling the "skin" parameter, which could be exploited by attackers to dislose the installation path or cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|