Show filters
217 Total Results
Displaying 131-140 of 217
Sort by:
Attacker Value
Unknown

CVE-2006-3175

Disclosure Date: June 23, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.
0
Attacker Value
Unknown

CVE-2006-3077

Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in guestbook.cfm in aXentGuestbook 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter.
0
Attacker Value
Unknown

CVE-2006-3062

Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in myPHP Guestbook 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown

CVE-2006-3063

Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11) name, and (12) text parameters in (b) admin/guestbook.php, and the (13) email, (14) homepage, (15) icq, (16) name, and (17) text parameters in (c) admin/edit.php.
0
Attacker Value
Unknown

CVE-2006-2994

Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in phazizGuestbook 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) url fields, and (4) text field (content parameter).
0
Attacker Value
Unknown

CVE-2006-2975

Disclosure Date: June 12, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description's details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-2854

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in iBWd Guestbook 1.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.
0
Attacker Value
Unknown

CVE-2006-2773

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does not verify user credentials, which allows remote attackers to edit arbitrary posts via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-2771

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.
0
Attacker Value
Unknown

CVE-2006-2772

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) headline parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0