Show filters
217 Total Results
Displaying 111-120 of 217
Sort by:
Attacker Value
Unknown

CVE-2006-5307

Disclosure Date: October 17, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls parameter in (1) add.php, (2) admin.php, (3) look.php, or (4) re.php.
0
Attacker Value
Unknown

CVE-2006-4889

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4) includes/admin.inc.php, (5) help.php, (6) smile.php, (7) entry.php; (8) adminhelp0.php, (9) adminhelp1.php, (10) adminhelp2.php, and (11) adminhelp3.php in (a) help/en and (b) help/de directories; and the (12) preview.php, (13) log.php, (14) index.php, (15) config.php, and (16) admin.php in the (c) admin directory, a different set of vectors than CVE-2006-4788.
0
Attacker Value
Unknown

CVE-2006-4788

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter.
0
Attacker Value
Unknown

CVE-2006-4325

Disclosure Date: August 24, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in gbook.php in Doika guestbook 2.5, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown

CVE-2006-4122

Disclosure Date: August 14, 2006 (last updated October 04, 2023)
Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php.
0
Attacker Value
Unknown

CVE-2006-4007

Disclosure Date: August 07, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.
0
Attacker Value
Unknown

CVE-2006-3937

Disclosure Date: July 31, 2006 (last updated October 04, 2023)
post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2006-3852

Disclosure Date: July 25, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Micro GuestBook allows remote attackers to execute arbitrary SQL commands via the (1) name or (2) comment ("text") fields.
0
Attacker Value
Unknown

CVE-2006-3837

Disclosure Date: July 25, 2006 (last updated October 04, 2023)
delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obtain the administrator's password hash after logout.
0
Attacker Value
Unknown

CVE-2006-3753

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash.
0