Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2009-4447
Disclosure Date: December 29, 2009 (last updated October 04, 2023)
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
0
Attacker Value
Unknown
CVE-2005-4880
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
0
Attacker Value
Unknown
CVE-2005-4879
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is also affected.
0
Attacker Value
Unknown
CVE-2006-1913
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0