Show filters
217 Total Results
Displaying 101-110 of 217
Sort by:
Attacker Value
Unknown

CVE-2007-0354

Disclosure Date: January 19, 2007 (last updated October 04, 2023)
SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2006-6487

Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the error[] parameter.
0
Attacker Value
Unknown

CVE-2007-0205

Disclosure Date: January 11, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.
0
Attacker Value
Unknown

CVE-2007-0202

Disclosure Date: January 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.
0
Attacker Value
Unknown

CVE-2007-0094

Disclosure Date: January 05, 2007 (last updated October 04, 2023)
Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.
0
Attacker Value
Unknown

CVE-2006-6278

Disclosure Date: December 04, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in @lex Guestbook 4.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.
0
Attacker Value
Unknown

CVE-2006-6279

Disclosure Date: December 04, 2006 (last updated October 04, 2023)
index.php in @lex Guestbook 4.0.1 allows remote attackers to obtain sensitive information via a skin parameter referencing a nonexistent skin, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2006-5804

Disclosure Date: November 08, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
0
Attacker Value
Unknown

CVE-2006-5651

Disclosure Date: November 07, 2006 (last updated October 04, 2023)
list.php in DigiOz Guestbook before 1.7.1 allows remote attackers to obtain sensitive information via a non-numeric page parameter, which displays the installation path in the resulting error message.
0
Attacker Value
Unknown

CVE-2006-5531

Disclosure Date: October 26, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter.
0