Show filters
217 Total Results
Displaying 171-180 of 217
Sort by:
Attacker Value
Unknown
CVE-2005-4597
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 1.7 allows remote attackers to inject arbitrary web script or HTML via the email parameter, as used by the email field, when signing a guestbook.
0
Attacker Value
Unknown
CVE-2005-3588
Disclosure Date: November 16, 2005 (last updated February 22, 2025)
SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field.
0
Attacker Value
Unknown
CVE-2005-3517
Disclosure Date: November 06, 2005 (last updated February 22, 2025)
Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.
0
Attacker Value
Unknown
CVE-2005-2650
Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.
0
Attacker Value
Unknown
CVE-2005-2162
Disclosure Date: July 06, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
0
Attacker Value
Unknown
CVE-2005-1685
Disclosure Date: May 20, 2005 (last updated February 22, 2025)
episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.
0
Attacker Value
Unknown
CVE-2005-1684
Disclosure Date: May 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields.
0
Attacker Value
Unknown
CVE-2005-1660
Disclosure Date: May 18, 2005 (last updated February 22, 2025)
HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password.
0
Attacker Value
Unknown
CVE-2005-1620
Disclosure Date: May 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
0
Attacker Value
Unknown
CVE-2005-1548
Disclosure Date: May 14, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
0