Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2010-4987
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.
0
Attacker Value
Unknown
CVE-2010-0978
Disclosure Date: March 16, 2010 (last updated October 04, 2023)
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.
0