mavili guestbook project
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 4 most recently published vulnerabilities affecting mavili guestbook project.
- CVE-2012-5299Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.7.5
- CVE-2012-5296Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) appr...4.3
- CVE-2012-5298Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.5.0
- CVE-2012-5297SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.7.5