Show filters
217 Total Results
Displaying 131-140 of 217
Sort by:
Attacker Value
Unknown
CVE-2006-3175
Disclosure Date: June 23, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.
0
Attacker Value
Unknown
CVE-2006-3077
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in guestbook.cfm in aXentGuestbook 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter.
0
Attacker Value
Unknown
CVE-2006-3062
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in myPHP Guestbook 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown
CVE-2006-3063
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11) name, and (12) text parameters in (b) admin/guestbook.php, and the (13) email, (14) homepage, (15) icq, (16) name, and (17) text parameters in (c) admin/edit.php.
0
Attacker Value
Unknown
CVE-2006-2994
Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in phazizGuestbook 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) url fields, and (4) text field (content parameter).
0
Attacker Value
Unknown
CVE-2006-2975
Disclosure Date: June 12, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description's details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-2854
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in iBWd Guestbook 1.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.
0
Attacker Value
Unknown
CVE-2006-2773
Disclosure Date: June 02, 2006 (last updated October 04, 2023)
admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does not verify user credentials, which allows remote attackers to edit arbitrary posts via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-2771
Disclosure Date: June 02, 2006 (last updated October 04, 2023)
admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.
0
Attacker Value
Unknown
CVE-2006-2772
Disclosure Date: June 02, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) headline parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0