Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2009-4447

Disclosure Date: December 29, 2009 (last updated October 04, 2023)
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
0
Attacker Value
Unknown

CVE-2005-4880

Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
0
Attacker Value
Unknown

CVE-2005-4879

Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is also affected.
0
Attacker Value
Unknown

CVE-2008-6562

Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-0335

Disclosure Date: January 18, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.
0
Attacker Value
Unknown

CVE-2006-3950

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
0
Attacker Value
Unknown

CVE-2006-3959

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.
0
Attacker Value
Unknown

CVE-2006-3960

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in top.php in X-Scripts X-Poll, probably 2.30, allows remote attackers to execute arbitrary SQL commands via the poll parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-2281

Disclosure Date: May 10, 2006 (last updated October 04, 2023)
X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access it.
0
Attacker Value
Unknown

CVE-2006-1913

Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0