Show filters
217 Total Results
Displaying 11-20 of 217
Sort by:
Attacker Value
Unknown
CVE-2018-17884
Disclosure Date: October 02, 2018 (last updated November 27, 2024)
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
0
Attacker Value
Unknown
CVE-2015-8351
Disclosure Date: September 11, 2017 (last updated November 26, 2024)
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.
0
Attacker Value
Unknown
CVE-2015-0871
Disclosure Date: February 07, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-5299
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.
0
Attacker Value
Unknown
CVE-2012-5298
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.
0
Attacker Value
Unknown
CVE-2012-5296
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp.
0
Attacker Value
Unknown
CVE-2012-5297
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2012-5103
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message parameter.
0
Attacker Value
Unknown
CVE-2011-5199
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
0
Attacker Value
Unknown
CVE-2011-5201
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information.
0