Show filters
217 Total Results
Displaying 171-180 of 217
Sort by:
Attacker Value
Unknown

CVE-2005-4597

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 1.7 allows remote attackers to inject arbitrary web script or HTML via the email parameter, as used by the email field, when signing a guestbook.
0
Attacker Value
Unknown

CVE-2005-3588

Disclosure Date: November 16, 2005 (last updated February 22, 2025)
SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field.
0
Attacker Value
Unknown

CVE-2005-3517

Disclosure Date: November 06, 2005 (last updated February 22, 2025)
Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.
0
Attacker Value
Unknown

CVE-2005-2650

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.
0
Attacker Value
Unknown

CVE-2005-2162

Disclosure Date: July 06, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
0
Attacker Value
Unknown

CVE-2005-1685

Disclosure Date: May 20, 2005 (last updated February 22, 2025)
episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.
0
Attacker Value
Unknown

CVE-2005-1684

Disclosure Date: May 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields.
0
Attacker Value
Unknown

CVE-2005-1660

Disclosure Date: May 18, 2005 (last updated February 22, 2025)
HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password.
0
Attacker Value
Unknown

CVE-2005-1620

Disclosure Date: May 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
0
Attacker Value
Unknown

CVE-2005-1548

Disclosure Date: May 14, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
0