Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-22402

Disclosure Date: January 18, 2024 (last updated January 27, 2024)
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2024-22401

Disclosure Date: January 18, 2024 (last updated January 27, 2024)
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2022-0732

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
Attacker Value
Unknown

CVE-2014-8294

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests 0.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) allmyphp_cookie cookie to admin.php or the (2) Username or (3) Password.
0
Attacker Value
Unknown

CVE-2014-8293

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the AMG_signin_topic parameter to index.php.
0
Attacker Value
Unknown

CVE-2008-1961

Disclosure Date: April 25, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.
0
Attacker Value
Unknown

CVE-2007-0172

Disclosure Date: January 11, 2007 (last updated April 24, 2024)
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.
0
Attacker Value
Unknown

CVE-2006-4993

Disclosure Date: September 26, 2006 (last updated April 24, 2024)
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _AMGconfig[cfg_serverpath] parameter in (1) modules/AllMyGuests/signin.php (aka the Nuke module) and (2) AllMyGuests/signin.php (aka the standalone).
0
Attacker Value
Unknown

CVE-2005-4222

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields.
0
Attacker Value
Unknown

CVE-2004-0285

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.