Lucene search

K

Max's Guestbook Security Vulnerabilities

prion
prion

Design/Logic Flaw

Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3)...

7.3AI Score

0.009EPSS

2012-10-04 05:55 PM
2
prion
prion

Cross site scripting

Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4)...

6.1AI Score

0.002EPSS

2012-10-04 05:55 PM
4
prion
prion

Improper access control

Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct...

7.1AI Score

0.005EPSS

2012-10-04 05:55 PM
1
cvelist
cvelist

CVE-2012-5297

SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id...

8.4AI Score

0.002EPSS

2012-10-04 05:00 PM
cvelist
cvelist

CVE-2012-5296

Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4)...

5.8AI Score

0.002EPSS

2012-10-04 05:00 PM
cvelist
cvelist

CVE-2012-5298

Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct...

6.5AI Score

0.005EPSS

2012-10-04 05:00 PM
cvelist
cvelist

CVE-2012-5299

Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3)...

6.8AI Score

0.009EPSS

2012-10-04 05:00 PM
myhack58
myhack58

Modoer. system of injection of several versions through the kill-vulnerability warning-the black bar safety net

Not to force the injection, to engage a station dig of, search it's a large station with this little impact on the issue to share learning, nonsense not say more, see our pork point~~~~~ First\core\modules\item\ajax. php start calling~ $do = trim($_GET['do']); $op = trim($_GET['op']); // allows...

0.6AI Score

2012-09-26 12:00 AM
9
cve
cve

CVE-2012-5103

Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message...

5.9AI Score

0.003EPSS

2012-09-23 05:55 PM
20
nvd
nvd

CVE-2012-5103

Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message...

5.8AI Score

0.003EPSS

2012-09-23 05:55 PM
prion
prion

Cross site scripting

Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message...

6.1AI Score

0.003EPSS

2012-09-23 05:55 PM
1
cvelist
cvelist

CVE-2012-5103

Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message...

5.8AI Score

0.003EPSS

2012-09-23 05:00 PM
securityvulns
securityvulns

Admidio 2.3.5 Multiple security vulnerabilities

Advisory: Admidio 2.3.5 Multiple security vulnerabilities Advisory ID: SSCHADV2012-019 Author: Stefan Schurtz Affected Software: Successfully tested on Admidio 2.3.5 Vendor URL: http://www.admidio.org/ Vendor Status: fixed ========================== Vulnerability...

0.7AI Score

2012-09-07 12:00 AM
36
xssed
xssed

Unfixed XSS vulnerability at www.hotel-pension-theresia.at

Security researcher Cr4t3r, has submitted on 09/02/2012 a cross-site-scripting (XSS) vulnerability affecting www.hotel-pension-theresia.at, which at the time of submission ranked 9021362 on the web according to Alexa. We manually validated and published a mirror of this vulnerability on...

-0.1AI Score

2012-09-02 12:00 AM
11
zdt
zdt

Admidio 2.3.5 Multiple security vulnerabilities

Exploit for php platform in category web...

7.1AI Score

2012-09-02 12:00 AM
8
exploitpack
exploitpack

Admidio 2.3.5 - Multiple Vulnerabilities

Admidio 2.3.5 - Multiple...

0.4AI Score

2012-09-02 12:00 AM
7
exploitdb

7.4AI Score

EPSS

2012-09-02 12:00 AM
59
packetstorm

-0.1AI Score

2012-09-01 12:00 AM
23
securityvulns
securityvulns

[CVE-2012-3873] Openconstructor CMS 3.12.0 'id' parameter multiple SQL injection vulnerabilities

Title###: Openconstructor CMS 3.12.0 'id' parameter multiple SQL injection vulnerabilities Affected Software###: http://www.openconstructor.org/ http://code.google.com/p/openconstructor/downloads/list http://esectorsolutions.com/about/whats-new/esector-news/detailed/?id=234 Description###:...

0.4AI Score

0.001EPSS

2012-08-13 12:00 AM
87
exploitpack
exploitpack

Openconstructor CMS 3.12.0 - id Multiple SQL Injections

Openconstructor CMS 3.12.0 - id Multiple SQL...

0.3AI Score

0.001EPSS

2012-08-08 12:00 AM
18
zdt
zdt

Openconstructor CMS 3.12.0 \'id\' Parameter Multiple SQL Injection

Exploit for php platform in category web...

7.1AI Score

2012-08-08 12:00 AM
32
exploitdb

6.6AI Score

EPSS

2012-08-08 12:00 AM
25
packetstorm

0.4AI Score

0.001EPSS

2012-08-04 12:00 AM
26
myhack58
myhack58

Its great foreign trade enterprise website management system multi-Agency high-risk vulnerabilities-vulnerability warning-the black bar safety net

Author: invincible gold record administration Affected versions: its great foreign trade enterprise website management system Studio edition v2. 7beat Download: http://down.chinaz.com/soft/30850.htm ① The guestbook to any user database plug horse Vulnerability files/cn/guestbook. asp Because...

0.3AI Score

2012-07-24 12:00 AM
6
securityvulns
securityvulns

Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks,...

1.6AI Score

2012-07-23 12:00 AM
40
securityvulns
securityvulns

MGB OpenSource Guestbook 0.6.9.1 Multiple security vulnerabilities

Advisory: MGB OpenSource Guestbook 0.6.9.1 Multiple security vulnerabilities Advisory ID: SSCHADV2012-017 Author: Stefan Schurtz Affected Software: Successfully tested on MGB OpenSource Guestbook 0.6.9.1 Vendor URL: http://www.m-gb.org Vendor Status: fixed ========================== Vulnerability.....

AI Score

2012-07-23 12:00 AM
10681
myhack58
myhack58

Hair red highlight personal website management system v1. 0. 0 to be implanted back door+injection+background holding Station-vulnerability warning-the black bar safety net

Author: invincible gold record administration Affected version: hair is red and bright personal website management system v1. 0. 0 Download: http://down.chinaz.com/soft/30614.htm First talk about this system right, the author seems to be very narcissistic, guestbook and everywhere the left is...

0.8AI Score

2012-07-20 12:00 AM
5
zdt

7.1AI Score

2012-07-18 12:00 AM
14
zdt
zdt

MGB OpenSource Guestbook 0.6.9.1 Cross Site Scripting / SQL Injection

Exploit for php platform in category web...

7.1AI Score

2012-07-17 12:00 AM
1780
packetstorm

-0.3AI Score

2012-07-17 12:00 AM
2762
zdt
zdt

Funeral Script PHP Cross Site Scripting / SQL Injection

Exploit for php platform in category web...

7.1AI Score

2012-07-12 12:00 AM
12
packetstorm

0.6AI Score

2012-07-12 12:00 AM
15
securityvulns
securityvulns

GuestBook Scripts PHP v1.5 - Multiple Web Vulnerabilites

Title: GuestBook Scripts PHP v1.5 - Multiple Web Vulnerabilites Date: 2012-06-11 References: http://www.vulnerability-lab.com/get_content.php?id=601 VL-ID: 601 Common Vulnerability Scoring System: 7.5 Introduction: GuestBook Script PHP is a script that is very easy to install, administer and use...

0.1AI Score

2012-07-09 12:00 AM
10695
securityvulns
securityvulns

Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks,...

1.6AI Score

0.947EPSS

2012-07-09 12:00 AM
58
exploitpack
exploitpack

Guestbook Scripts PHP 1.5 - Multiple Vulnerabilities

Guestbook Scripts PHP 1.5 - Multiple...

0.5AI Score

2012-07-05 12:00 AM
10
exploitdb

7.4AI Score

2012-07-05 12:00 AM
19
packetstorm

0.5AI Score

2012-07-05 12:00 AM
23
zdt
zdt

GuestBook Scripts PHP v1.5 - Multiple Vulnerabilities

Exploit for php platform in category web...

7.1AI Score

2012-07-03 12:00 AM
22
vulnerlab

7.1AI Score

2012-06-16 12:00 AM
13
vulnerlab

0.5AI Score

2012-06-16 12:00 AM
12
vulnerlab

7.1AI Score

2012-06-10 12:00 AM
19
vulnerlab

0.4AI Score

2012-06-10 12:00 AM
15
packetstorm

0.3AI Score

2012-05-19 12:00 AM
74
securityvulns
securityvulns

seditio-build170.20120302_sql_injection_CSRF_info_disclosure_XSS.txt

============================================================ Vulnerable Software: Seditio 170 (seditio-build170.20120302) Downloaded from:http://www.neocrome.net/files/code/seditio-build170.20120302.rar (MD5 SUM:beb6adc6abb56f947698c1efdbae9430 seditio-build170.20120302.rar)...

-0.1AI Score

2012-04-23 12:00 AM
49
zdt
zdt

Agit-Run20 Guestbook SQL injection Vulnerability

Exploit for asp platform in category web...

7.1AI Score

2012-04-15 12:00 AM
11
packetstorm

0.5AI Score

2012-04-12 12:00 AM
12
packetstorm

-0.2AI Score

2012-04-07 12:00 AM
21
exploitpack
exploitpack

w-CMS 2.0.1 - Multiple Vulnerabilities

w-CMS 2.0.1 - Multiple...

0.1AI Score

2012-04-06 12:00 AM
14
exploitdb

7.4AI Score

EPSS

2012-04-06 12:00 AM
21
securityvulns
securityvulns

Lastguru ASP GuestBook 'View.asp' - SQL Injection Vulnerability

Title: Lastguru ASP GuestBook 'View.asp' - SQL Injection Vulnerability Product : Lastguru ASP GuestBook Version : Free Version Vendor: http://www.LastGuru.com Class: Input Validation Error CVE: Remote: Yes Local: No Published: 2012-03-04 Updated: Impact : Medium (CVSSv2 Base : 7.5,...

0.3AI Score

2012-03-19 12:00 AM
46
Total number of security vulnerabilities2444