Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2012-5299
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.
0
Attacker Value
Unknown
CVE-2012-5298
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.
0
Attacker Value
Unknown
CVE-2012-5296
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp.
0
Attacker Value
Unknown
CVE-2012-5297
Disclosure Date: October 04, 2012 (last updated October 05, 2023)
SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.
0