Show filters
217 Total Results
Displaying 41-50 of 217
Sort by:
Attacker Value
Unknown
CVE-2008-6934
Disclosure Date: August 11, 2009 (last updated October 04, 2023)
Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-2648
Disclosure Date: July 30, 2009 (last updated October 04, 2023)
FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function.
0
Attacker Value
Unknown
CVE-2009-2448
Disclosure Date: July 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-2447
Disclosure Date: July 13, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display parameter.
0
Attacker Value
Unknown
CVE-2009-2440
Disclosure Date: July 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown
CVE-2009-2441
Disclosure Date: July 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.
0
Attacker Value
Unknown
CVE-2009-2337
Disclosure Date: July 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter.
0
Attacker Value
Unknown
CVE-2009-2307
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php.
0
Attacker Value
Unknown
CVE-2009-2224
Disclosure Date: June 26, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter.
0
Attacker Value
Unknown
CVE-2003-1571
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected.
0