The remote web server contains an ASP application that is affected by
several issues.
Description :
The remote host is running the Episodex Guestbook, a guestbook written
in ASP.
The version of Episodex installed on the remote host does not validate
input to various fields in the default.asp script before using it to
generate dynamic HTML.
In addition, an unauthenticated remote attacker can edit settings by
accessing the applications admin.asp script directly.