Lucene search

K

Max's Guestbook Security Vulnerabilities

exploitdb

7.4AI Score

2023-08-04 12:00 AM
90
zdt

7.1AI Score

2023-08-04 12:00 AM
64
packetstorm

7.1AI Score

2023-08-02 12:00 AM
115
cve
cve

CVE-2023-3476

A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It....

6.1CVSS

6AI Score

0.001EPSS

2023-06-30 07:15 AM
14
nvd
nvd

CVE-2023-3476

A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It....

6.1CVSS

4.5AI Score

0.001EPSS

2023-06-30 07:15 AM
prion
prion

Cross site scripting

A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It....

6.1CVSS

6AI Score

0.001EPSS

2023-06-30 07:15 AM
5
cvelist
cvelist

CVE-2023-3476 SimplePHPscripts GuestBook Script URL Parameter preview.php cross site scripting

A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It....

3.5CVSS

6.2AI Score

0.001EPSS

2023-06-30 07:00 AM
nvd
nvd

CVE-2023-3465

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site...

6.1CVSS

4.5AI Score

0.001EPSS

2023-06-29 09:15 PM
cve
cve

CVE-2023-3465

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site...

6.1CVSS

6.1AI Score

0.001EPSS

2023-06-29 09:15 PM
12
nvd
nvd

CVE-2023-3464

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to...

6.1CVSS

4.5AI Score

0.001EPSS

2023-06-29 09:15 PM
cve
cve

CVE-2023-3464

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to...

6.1CVSS

6AI Score

0.001EPSS

2023-06-29 09:15 PM
14
prion
prion

Cross site scripting

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to...

6.1CVSS

6.1AI Score

0.001EPSS

2023-06-29 09:15 PM
6
prion
prion

Cross site scripting

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site...

6.1CVSS

6.1AI Score

0.001EPSS

2023-06-29 09:15 PM
6
cvelist
cvelist

CVE-2023-3465 SimplePHPscripts Classified Ads Script HTTP POST Request user.php cross site scripting

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site...

3.5CVSS

6.3AI Score

0.001EPSS

2023-06-29 09:00 PM
cvelist
cvelist

CVE-2023-3464 SimplePHPscripts Classified Ads Script URL Parameter preview.php cross site scripting

A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to...

3.5CVSS

6.2AI Score

0.001EPSS

2023-06-29 08:31 PM
packetstorm

7.1AI Score

2023-06-28 12:00 AM
130
cve
cve

CVE-2023-22985

Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and...

6.1CVSS

6AI Score

0.001EPSS

2023-04-06 03:15 PM
14
nvd
nvd

CVE-2023-22985

Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and...

6.1CVSS

6AI Score

0.001EPSS

2023-04-06 03:15 PM
prion
prion

Cross site scripting

Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and...

6.1CVSS

6AI Score

0.001EPSS

2023-04-06 03:15 PM
5
cvelist
cvelist

CVE-2023-22985

Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and...

6.2AI Score

0.001EPSS

2023-04-06 12:00 AM
packetstorm

-0.6AI Score

2023-01-12 12:00 AM
596
cve
cve

CVE-2014-125053

A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is.....

9.8CVSS

9.8AI Score

0.01EPSS

2023-01-06 11:15 PM
22
prion
prion

Sql injection

A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is.....

9.8CVSS

8.1AI Score

0.01EPSS

2023-01-06 11:15 PM
6
cve
cve

CVE-2009-2440

Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page...

5.8AI Score

0.002EPSS

2022-10-03 04:24 PM
21
cve
cve

CVE-2009-2448

Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party...

5.7AI Score

0.001EPSS

2022-10-03 04:24 PM
26
cvelist
cvelist

CVE-2009-2448

Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party...

5.6AI Score

0.001EPSS

2022-10-03 04:24 PM
1
cvelist
cvelist

CVE-2009-2440

Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page...

5.7AI Score

0.002EPSS

2022-10-03 04:24 PM
cvelist
cvelist

CVE-2009-2447

Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display...

5.8AI Score

0.001EPSS

2022-10-03 04:24 PM
cve
cve

CVE-2009-2447

Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display...

5.9AI Score

0.001EPSS

2022-10-03 04:24 PM
29
cvelist
cvelist

CVE-2009-3189

Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term...

5.7AI Score

0.002EPSS

2022-10-03 04:23 PM
cve
cve

CVE-2009-3189

Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term...

5.7AI Score

0.002EPSS

2022-10-03 04:23 PM
23
cve
cve

CVE-2002-2339

Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left...

5.9AI Score

0.002EPSS

2022-10-03 04:23 PM
22
cvelist
cvelist

CVE-2002-2339

Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left...

5.7AI Score

0.002EPSS

2022-10-03 04:23 PM
cve
cve

CVE-2005-4649

Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from...

5.8AI Score

0.003EPSS

2022-10-03 04:22 PM
23
cvelist
cvelist

CVE-2005-4649

Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from...

5.7AI Score

0.003EPSS

2022-10-03 04:22 PM
cve
cve

CVE-2005-4880

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4)...

6.5AI Score

0.004EPSS

2022-10-03 04:22 PM
18
cvelist
cvelist

CVE-2005-4880

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4)...

6.2AI Score

0.004EPSS

2022-10-03 04:22 PM
cvelist
cvelist

CVE-2005-1412

SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD...

8.4AI Score

0.001EPSS

2022-10-03 04:22 PM
1
cve
cve

CVE-2005-1412

SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD...

8.8AI Score

0.001EPSS

2022-10-03 04:22 PM
23
cve
cve

CVE-2003-1293

Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the...

6AI Score

0.001EPSS

2022-10-03 04:15 PM
26
cvelist
cvelist

CVE-2003-1293

Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the...

5.8AI Score

0.001EPSS

2022-10-03 04:15 PM
cve
cve

CVE-2012-3873

Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or....

8.2AI Score

0.001EPSS

2022-10-03 04:15 PM
23
cvelist
cvelist

CVE-2012-3873

Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or....

8AI Score

0.001EPSS

2022-10-03 04:15 PM
cve
cve

CVE-2021-36830

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at...

4.8CVSS

4.8AI Score

0.001EPSS

2022-09-30 05:15 PM
32
9
nvd
nvd

CVE-2021-36830

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at...

4.8CVSS

0.001EPSS

2022-09-30 05:15 PM
1
prion
prion

Cross site scripting

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at...

4.8CVSS

4.9AI Score

0.001EPSS

2022-09-30 05:15 PM
5
cvelist
cvelist

CVE-2021-36830 WordPress Comment Guestbook plugin <= 0.8.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin &lt;= 0.8.0 at...

4.8CVSS

5.1AI Score

0.001EPSS

2022-09-26 12:00 AM
wpvulndb
wpvulndb

Comment Guestbook <= 0.8.0 - Admin+ Stored Cross-Site Scripting

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...

4.8CVSS

2.3AI Score

0.001EPSS

2022-09-26 12:00 AM
14
patchstack
patchstack

WordPress Comment Guestbook plugin <= 0.8.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Asif Nawaz Minhas (Patchstack Alliance) in WordPress Comment Guestbook plugin (versions &lt;= 0.8.0). Solution No patched version...

4.8CVSS

3AI Score

0.001EPSS

2022-09-26 12:00 AM
10
cve
cve

CVE-2017-20089

A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated...

6.1CVSS

6AI Score

0.001EPSS

2022-06-23 05:15 AM
22
6
Total number of security vulnerabilities2444