Show filters
217 Total Results
Displaying 101-110 of 217
Sort by:
Attacker Value
Unknown
CVE-2007-0354
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2006-6487
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the error[] parameter.
0
Attacker Value
Unknown
CVE-2007-0205
Disclosure Date: January 11, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.
0
Attacker Value
Unknown
CVE-2007-0202
Disclosure Date: January 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.
0
Attacker Value
Unknown
CVE-2007-0094
Disclosure Date: January 05, 2007 (last updated October 04, 2023)
Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.
0
Attacker Value
Unknown
CVE-2006-6278
Disclosure Date: December 04, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in @lex Guestbook 4.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.
0
Attacker Value
Unknown
CVE-2006-6279
Disclosure Date: December 04, 2006 (last updated October 04, 2023)
index.php in @lex Guestbook 4.0.1 allows remote attackers to obtain sensitive information via a skin parameter referencing a nonexistent skin, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2006-5804
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
0
Attacker Value
Unknown
CVE-2006-5651
Disclosure Date: November 07, 2006 (last updated October 04, 2023)
list.php in DigiOz Guestbook before 1.7.1 allows remote attackers to obtain sensitive information via a non-numeric page parameter, which displays the installation path in the resulting error message.
0
Attacker Value
Unknown
CVE-2006-5531
Disclosure Date: October 26, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter.
0