VYPR
Unrated severityNVD Advisory· Published May 30, 2006· Updated Jun 16, 2026

CVE-2006-2637

CVE-2006-2637

Description

Cross-site scripting (XSS) vulnerability in view.php in TuttoPhp (1) Morris Guestbook 1, (2) Pretty Guestbook 1, and (3) Smile Guestbook 1 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the pagina parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:tuttophp:morris_guestbook:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tuttophp:morris_guestbook:*:*:*:*:*:*:*:*
    • (no CPE)range: =1
  • cpe:2.3:a:tuttophp:pretty_guestbook:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tuttophp:pretty_guestbook:*:*:*:*:*:*:*:*
    • (no CPE)range: =1
  • cpe:2.3:a:tuttophp:smile_guestbook:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tuttophp:smile_guestbook:*:*:*:*:*:*:*:*
    • (no CPE)range: =1

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.