Show filters
217 Total Results
Displaying 121-130 of 217
Sort by:
Attacker Value
Unknown

CVE-2006-3752

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters.
0
Attacker Value
Unknown

CVE-2006-3618

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.
0
Attacker Value
Unknown

CVE-2006-3616

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file.
0
Attacker Value
Unknown

CVE-2006-3617

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) message (aka comments), (3) website, and (4) email parameters, which bypasses XSS protection mechanisms that check for SCRIPT tags but not others, as demonstrated by a javascript URI in an onMouseOver attribute and the src attribute in an iframe tag. NOTE: some vectors might overlap CVE-2006-2975, although the use of alternate manipulations makes it unclear.
0
Attacker Value
Unknown

CVE-2006-3568

Disclosure Date: July 13, 2006 (last updated February 09, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) nickname parameters.
0
Attacker Value
Unknown

CVE-2006-3526

Disclosure Date: July 12, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Sport-slo Advanced Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) name and (2) form parameters.
0
Attacker Value
Unknown

CVE-2006-3295

Disclosure Date: June 29, 2006 (last updated February 09, 2024)
Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown

CVE-2006-3296

Disclosure Date: June 29, 2006 (last updated October 04, 2023)
SQL injection vulnerability in view.php in Open Guestbook 0.5 allows remote attackers to execute arbitrary SQL commands via the offset parameter.
0
Attacker Value
Unknown

CVE-2006-3211

Disclosure Date: June 24, 2006 (last updated February 09, 2024)
Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject Javascript code via a javascript URI in an img bbcode tag in the comments parameter.
0
Attacker Value
Unknown

CVE-2006-3212

Disclosure Date: June 24, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject web script or HTML via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0