Back

CVE-2004-2138

Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
allwebscripts mysqlguest *

GitHub Security Advisory GHSA-fff7-qc35-c5hv

Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 1.47%

Top 28% most likely to be exploited

Threat Score 27.6 / 100

Data Sources

NVD EPSS GitHub