Show filters
217 Total Results
Displaying 31-40 of 217
Sort by:
Attacker Value
Unknown

CVE-2009-4678

Disclosure Date: March 08, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown

CVE-2009-4447

Disclosure Date: December 29, 2009 (last updated October 04, 2023)
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
0
Attacker Value
Unknown

CVE-2009-3493

Disclosure Date: September 30, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.
0
Attacker Value
Unknown

CVE-2009-3421

Disclosure Date: September 25, 2009 (last updated February 14, 2024)
login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
Attacker Value
Unknown

CVE-2009-3327

Disclosure Date: September 23, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-3328

Disclosure Date: September 23, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-3189

Disclosure Date: September 15, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.
0
Attacker Value
Unknown

CVE-2008-7140

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: a third party has been reported that the test parameter is not used in @lex Guestbook.
0
Attacker Value
Unknown

CVE-2008-7007

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.
0
Attacker Value
Unknown

CVE-2008-7006

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.
0