Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2005-1429
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.
0
Attacker Value
Unknown
CVE-2004-2428
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password.
0