Show filters
217 Total Results
Displaying 91-100 of 217
Sort by:
Attacker Value
Unknown

CVE-2007-1304

Disclosure Date: March 07, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.
0
Attacker Value
Unknown

CVE-2007-1302

Disclosure Date: March 07, 2007 (last updated October 04, 2023)
SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected.
0
Attacker Value
Unknown

CVE-2007-1305

Disclosure Date: March 07, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in add2.php in Sava's Guestbook 23.11.2006 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) country, (3) email, and (4) website parameters.
0
Attacker Value
Unknown

CVE-2007-1192

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.
0
Attacker Value
Unknown

CVE-2006-7076

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.
0
Attacker Value
Unknown

CVE-2007-1165

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.
0
Attacker Value
Unknown

CVE-2006-7077

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.
0
Attacker Value
Unknown

CVE-2007-0926

Disclosure Date: February 14, 2007 (last updated October 04, 2023)
The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.
0
Attacker Value
Unknown

CVE-2007-0542

Disclosure Date: January 29, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.
0
Attacker Value
Unknown

CVE-2007-0530

Disclosure Date: January 26, 2007 (last updated November 08, 2023)
Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804. NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use
0