Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown
CVE-2006-1070
Disclosure Date: March 08, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter.
0
Attacker Value
Unknown
CVE-2006-0540
Disclosure Date: February 04, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-0541
Disclosure Date: February 04, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "posting new messages."
0
Attacker Value
Unknown
CVE-2006-0501
Disclosure Date: February 01, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the Name field, when registering a user.
0
Attacker Value
Unknown
CVE-2006-0500
Disclosure Date: February 01, 2006 (last updated February 22, 2025)
MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL.
0
Attacker Value
Unknown
CVE-2005-1620
Disclosure Date: May 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
0
Attacker Value
Unknown
CVE-2005-1425
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.
0
Attacker Value
Unknown
CVE-2005-0423
Disclosure Date: April 27, 2005 (last updated February 22, 2025)
SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.
0
Attacker Value
Unknown
CVE-2005-0424
Disclosure Date: April 27, 2005 (last updated February 22, 2025)
Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.
0
Attacker Value
Unknown
CVE-2002-1410
Disclosure Date: April 11, 2003 (last updated February 22, 2025)
Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.
0