VYPR

Htmlgear Guestgear

by Lycos

CVEs (2)

  • CVE-2002-1493Apr 2, 2003
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag.

  • CVE-2006-2808Jun 5, 2006
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Lycos Tripod htmlGEAR guestGEAR (aka Guest Gear) allows remote attackers to inject arbitrary web script or HTML via a guestbook post containing a javascript URI in the SRC attribute of the BR element after an extra "iframe" tagname within that element, followed by a double ">", which might bypass cleansing operations.