Loading vulnerability details…
CVSS v3.1
N/A
EPSS
2.58%
Published
Sep 18, 2007
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.
Weaknesses (CWE)
Affected Products (1)
References (10)