Show filters
217 Total Results
Displaying 11-20 of 217
Sort by:
Attacker Value
Unknown

CVE-2018-17884

Disclosure Date: October 02, 2018 (last updated November 27, 2024)
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
0
Attacker Value
Unknown

CVE-2015-8351

Disclosure Date: September 11, 2017 (last updated November 26, 2024)
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.
0
Attacker Value
Unknown

CVE-2015-0871

Disclosure Date: February 07, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-5299

Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.
0
Attacker Value
Unknown

CVE-2012-5298

Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.
0
Attacker Value
Unknown

CVE-2012-5296

Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp.
0
Attacker Value
Unknown

CVE-2012-5297

Disclosure Date: October 04, 2012 (last updated October 05, 2023)
SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2012-5103

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message parameter.
0
Attacker Value
Unknown

CVE-2011-5199

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
0
Attacker Value
Unknown

CVE-2011-5201

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information.
0