Show filters
217 Total Results
Displaying 181-190 of 217
Sort by:
Attacker Value
Unknown

CVE-2005-1557

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
0
Attacker Value
Unknown

CVE-2005-1425

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.
0
Attacker Value
Unknown

CVE-2005-1412

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.
0
Attacker Value
Unknown

CVE-2005-1429

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.
0
Attacker Value
Unknown

CVE-2005-0915

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
0
Attacker Value
Unknown

CVE-2005-0423

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.
0
Attacker Value
Unknown

CVE-2005-0424

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.
0
Attacker Value
Unknown

CVE-2005-0476

Disclosure Date: March 30, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.
0
Attacker Value
Unknown

CVE-2004-1213

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter.
0
Attacker Value
Unknown

CVE-2004-1554

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.
0