Synopsis
The remote web server has an application that is affected by a cross-site scripting vulnerability.
Description
The remote server is running Ocean12 GuestBook, a set of scripts to manage an interactive guestbook.
An attacker may use this module to inject malicious HTML code in your site, which may be used to steal users' cookies or to simply annoy them.
Solution
Disable this software.
Plugin Details
File Name: ocean12_guestbook_xss.nasl
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 7329
CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990