CVE-2002-0732 describes a cross-site scripting (XSS) vulnerability in MyGuestbook 1.0 from levcgi.com. This flaw allows remote attackers to inject arbitrary script or HTML into web pages through fields like the username or comments. With a CVSS score of 7.5, this vulnerability is considered high severity, as it can be exploited remotely with low attack complexity and no authentication, potentially leading to information disclosure, data alteration, and denial of service. While not listed in CISA's KEV catalog, exploit code is publicly available via ExploitDB, and the CVE has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:levcgi.com:myguestbook:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.