Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2009-2440
Disclosure Date: July 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown
CVE-2009-2337
Disclosure Date: July 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter.
0
Attacker Value
Unknown
CVE-2009-0424
Disclosure Date: February 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-5852
Disclosure Date: January 06, 2009 (last updated October 04, 2023)
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.
0
Attacker Value
Unknown
CVE-2007-2101
Disclosure Date: April 18, 2007 (last updated October 04, 2023)
FAC Guestbook 3.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/gbdb.mdb. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-1933
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.
0
Attacker Value
Unknown
CVE-2003-1241
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters.
0
Attacker Value
Unknown
CVE-2002-0551
Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.
0
Attacker Value
Unknown
CVE-2002-0550
Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.
0