Show filters
217 Total Results
Displaying 51-60 of 217
Sort by:
Attacker Value
Unknown
CVE-2005-4880
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
0
Attacker Value
Unknown
CVE-2005-4879
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is also affected.
0
Attacker Value
Unknown
CVE-2009-0810
Disclosure Date: March 04, 2009 (last updated October 04, 2023)
SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.
0
Attacker Value
Unknown
CVE-2008-6368
Disclosure Date: March 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter.
0
Attacker Value
Unknown
CVE-2008-6359
Disclosure Date: March 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.
0
Attacker Value
Unknown
CVE-2009-0498
Disclosure Date: February 10, 2009 (last updated October 04, 2023)
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.
0
Attacker Value
Unknown
CVE-2009-0424
Disclosure Date: February 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-5852
Disclosure Date: January 06, 2009 (last updated October 04, 2023)
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.
0
Attacker Value
Unknown
CVE-2008-4751
Disclosure Date: October 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597.
0
Attacker Value
Unknown
CVE-2008-3847
Disclosure Date: August 27, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0