Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2009-2440

Disclosure Date: July 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown

CVE-2009-2337

Disclosure Date: July 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter.
0
Attacker Value
Unknown

CVE-2009-0424

Disclosure Date: February 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-5852

Disclosure Date: January 06, 2009 (last updated October 04, 2023)
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.
0
Attacker Value
Unknown

CVE-2007-2101

Disclosure Date: April 18, 2007 (last updated October 04, 2023)
FAC Guestbook 3.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/gbdb.mdb. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-1933

Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.
0
Attacker Value
Unknown

CVE-2003-1241

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters.
0
Attacker Value
Unknown

CVE-2002-0551

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.
0
Attacker Value
Unknown

CVE-2002-0550

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.
0