Show filters
217 Total Results
Displaying 191-200 of 217
Sort by:
Attacker Value
Unknown

CVE-2004-2354

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
0
Attacker Value
Unknown

CVE-2004-2428

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password.
0
Attacker Value
Unknown

CVE-2004-1952

Disclosure Date: April 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.
0
Attacker Value
Unknown

CVE-2003-1293

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook.
0
Attacker Value
Unknown

CVE-2003-1534

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.
0
Attacker Value
Unknown

CVE-2003-1314

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.
0
Attacker Value
Unknown

CVE-2003-1348

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.
0
Attacker Value
Unknown

CVE-2003-1541

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.
0
Attacker Value
Unknown

CVE-2003-1241

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters.
0
Attacker Value
Unknown

CVE-2003-1535

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.
0