Description
|
|
Multiple vulnerabilities have been identified in X-script GuestBook, which could be exploited by remote attackers to execute arbitrary SQL queries. These issues are caused by input validation errors in the "mes_add.php" script that does not validate the "name", "email", "icq", and "website" parameters before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.
|